<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device sensor information not getting to ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151259#M590857</link>
    <description>&lt;P&gt;Did you start from the very beginning? Can you login to the switch and see lldp / cdp data locally? i.e. what's the output of:&lt;BR /&gt;&lt;STRONG&gt;show lldp neighbors gi1/0/27 d&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;show cdp neighbors gi1/0/27 d&lt;/STRONG&gt;&lt;BR /&gt;And if you see output from both of the above, what does device-sensor on the 9300 show you? ex:&lt;BR /&gt;&lt;STRONG&gt;show device-sensor cache interface gi1/0/27&lt;/STRONG&gt;&lt;BR /&gt;Once you've verified the data is at the switch level, you can move upward in the stream to, eventually, ISE.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;David&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 18:45:33 GMT</pubDate>
    <dc:creator>davidgfriedman</dc:creator>
    <dc:date>2024-07-25T18:45:33Z</dc:date>
    <item>
      <title>Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5038780#M588061</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Got a bit of a weird problem trying to profile some Cisco 9120 APs on ISE 3.1&lt;/P&gt;&lt;P&gt;Short version is that I have 3 APs connected onto a Catalyst 9300 with 802.1x enabled. 2 of them are successfully being profiled as Cisco APs by ISE (and thus hitting the related Auth Policy) one of them is not.&lt;/P&gt;&lt;P&gt;Checking the Endpoints in ISE the 2 which are being profiled correctly have all of the relevant attributes I'd expect to see (DHCP, LLDP and CDP) under "Attributes &amp;gt; Other Attributes". The one which isn't working has none of this information listed.&lt;/P&gt;&lt;P&gt;I've checked the device-sensor information on the switch (show device-sensor cache interface xx) for each of the AP's and they all have the correct details listed there.&lt;/P&gt;&lt;P&gt;I've cleared the authentication sessions, shut/no shut the switch port (many times!) and tried everything I can think of.&lt;/P&gt;&lt;P&gt;Global config must be correct (I assume) as the info is being passed for the other 2 AP's, and the interface config for all 3 is identical.&lt;/P&gt;&lt;P&gt;I've completely run out of ideas so reaching out for some help if anyone has any ideas?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 13:37:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5038780#M588061</guid>
      <dc:creator>david-mead</dc:creator>
      <dc:date>2024-03-13T13:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5039757#M588093</link>
      <description>&lt;P&gt;Verify RADIUS Accounting is properly configured on your third network device. Device Sensor information is sent to ISE via RADIUS Accounting.&lt;/P&gt;
&lt;P&gt;See &lt;LI-MESSAGE title="ISE Secure Wired Access Prescriptive Deployment Guide" uid="3641515" url="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/m-p/3641515#U3641515" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&amp;gt; &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-953134665" rel="nofollow noopener noreferrer" target="_blank"&gt;Preparing a Switch for Identity-Based Network Access&lt;/A&gt; for details.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 14:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5039757#M588093</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-03-14T14:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5039819#M588099</link>
      <description>&lt;P&gt;Isn't that information sent from the switch? As I say the switch is successfully sending all of the device sensor information for the other devices attached to it, so I'm confident the AAA config is correct.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 15:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5039819#M588099</guid>
      <dc:creator>david-mead</dc:creator>
      <dc:date>2024-03-14T15:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151238#M590855</link>
      <description>&lt;P&gt;Having the same issue with a Catalyst 9300 switch and an AP model&amp;nbsp;C9120AXI.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On ISE I can only see the LLDP device sensor information, but not the CDP.&lt;/P&gt;
&lt;P&gt;Did u find the solution to this?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 17:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151238#M590855</guid>
      <dc:creator>Carlos T</dc:creator>
      <dc:date>2024-07-25T17:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151259#M590857</link>
      <description>&lt;P&gt;Did you start from the very beginning? Can you login to the switch and see lldp / cdp data locally? i.e. what's the output of:&lt;BR /&gt;&lt;STRONG&gt;show lldp neighbors gi1/0/27 d&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;show cdp neighbors gi1/0/27 d&lt;/STRONG&gt;&lt;BR /&gt;And if you see output from both of the above, what does device-sensor on the 9300 show you? ex:&lt;BR /&gt;&lt;STRONG&gt;show device-sensor cache interface gi1/0/27&lt;/STRONG&gt;&lt;BR /&gt;Once you've verified the data is at the switch level, you can move upward in the stream to, eventually, ISE.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 18:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151259#M590857</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2024-07-25T18:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151261#M590858</link>
      <description>&lt;P&gt;I can see CDP and LLDP information of the connected device on the switch. Output of command "show device-sensor cache all" shows CDP and LLDP attributes.&lt;/P&gt;
&lt;P&gt;On ISE "Endpoint Classification / Attributes / Other Attributes",&amp;nbsp; when looking for the mac address of the Access Point (connected to the switch that is configured with device sensor), it is showing only the LLDP information, but nothing of CDP information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 18:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5151261#M590858</guid>
      <dc:creator>Carlos T</dc:creator>
      <dc:date>2024-07-25T18:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5152692#M590918</link>
      <description>&lt;P&gt;Just to say we never found the solution. Ended up adding the MAC addresses of the AP's to MAB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do figure it out though let me know.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 07:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5152692#M590918</guid>
      <dc:creator>david-mead</dc:creator>
      <dc:date>2024-07-29T07:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Device sensor information not getting to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5152702#M590920</link>
      <description>&lt;P&gt;The implementation we are running on the network is "closed mode" (endpoint blocked access to the network if authentication fails).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for testing I enabled "open mode" (authentication open, and a permit ip any any acl on the switchport), so then ISE can see the endpoint (even if it fails authentication), and after that I see ISE profiled correctly the endpoint, and also I can see all the CDP information on&amp;nbsp;&lt;SPAN&gt;"Endpoint Classification / Attributes / Other Attributes".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have a case open so waiting the reply of the TAC, but from the tests, looks like some attributes (CDP for example) are only visible on ISE after the endpoint is profiled. But other attributes (LLDP for example) are visible on ISE before/after the endpoint is profiled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think we need to go with the phased approach of "open mode" first, so ISE can profile correctly the endpoint, and then go to "closed mode", so after that the ISE knows all attributes of the endpoint as it was profiled before.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 07:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-information-not-getting-to-ise/m-p/5152702#M590920</guid>
      <dc:creator>Carlos T</dc:creator>
      <dc:date>2024-07-29T07:55:36Z</dc:date>
    </item>
  </channel>
</rss>

