<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with Triggered Endpoint NMAP Scan for Canon Printers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296984#M596674</link>
    <description>&lt;P&gt;Manual NMAP works perfectly as expected. Not sure why it is not triggering an automatic NMAP scan&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect that ISE PSN is not getting&amp;nbsp;IP addresses to MAC binding information via RADIUS&amp;nbsp;(Framed IP Address)&lt;/P&gt;
&lt;P&gt;But I am not sure how to check on ISE if PSN is getting the IP addresses to the MAC binding information via RADIUS&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jun 2025 17:43:54 GMT</pubDate>
    <dc:creator>jitendrac</dc:creator>
    <dc:date>2025-06-05T17:43:54Z</dc:date>
    <item>
      <title>Issue with Triggered Endpoint NMAP Scan for Canon Printers</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296478#M596643</link>
      <description>&lt;P data-start="212" data-end="325"&gt;We are currently facing an issue with the Triggered Endpoint NMAP Scan functionality on our Cisco ISE 3.3 deployment.&lt;/P&gt;
&lt;P data-start="327" data-end="500"&gt;We are attempting to perform NMAP scans on Canon printer devices to obtain detailed information such as model and OS. These printers are configured with static IP addresses.&lt;/P&gt;
&lt;P data-start="502" data-end="552"&gt;To enable this, we have taken the following steps:&lt;/P&gt;
&lt;UL data-start="554" data-end="948"&gt;
&lt;LI data-start="554" data-end="650"&gt;
&lt;P data-start="556" data-end="650"&gt;Enabled the NMAP probe on the PSN as per the &lt;STRONG data-start="601" data-end="631"&gt;ISE Profiling Design Guide&lt;/STRONG&gt; (Cisco Community).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="651" data-end="737"&gt;
&lt;P data-start="653" data-end="737"&gt;Allowed all required NMAP ports from the PSN to the subnet range of the printer IPs.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="738" data-end="948"&gt;
&lt;P data-start="740" data-end="948"&gt;We are using the default Cisco-provided profiler policy for Canon devices: &lt;STRONG data-start="815" data-end="833"&gt;"Canon-Device"&lt;/STRONG&gt;, which has defulat condition with an NMAP action based on the OUI (refer to the attached screenshot for reference).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We are observing that&lt;/P&gt;
&lt;UL data-start="984" data-end="1280"&gt;
&lt;LI data-start="984" data-end="1048"&gt;
&lt;P data-start="986" data-end="1048"&gt;The printer devices are successfully authenticating using MAB.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1049" data-end="1142"&gt;
&lt;P data-start="1051" data-end="1142"&gt;The profiling policy &lt;STRONG data-start="1072" data-end="1090"&gt;"Canon-Device"&lt;/STRONG&gt; is being matched correctly in the attribute filter.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="950" data-end="982"&gt;Despite the above configuration:&lt;/P&gt;
&lt;UL data-start="984" data-end="1280"&gt;
&lt;LI data-start="1143" data-end="1280"&gt;
&lt;P data-start="1145" data-end="1280"&gt;we do not observe any triggered NMAP scans.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1143" data-end="1280"&gt;
&lt;P data-start="1145" data-end="1280"&gt;Attributes such as &lt;CODE data-start="1217" data-end="1232"&gt;NmapScanCount&lt;/CODE&gt; and &lt;CODE data-start="1237" data-end="1255"&gt;LastNmapScanTime&lt;/CODE&gt; are not being populated.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1282" data-end="1410"&gt;I would appreciate your assistance in identifying the root cause and helping us enable successful NMAP scans for these devices.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296478#M596643</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-06-04T09:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Triggered Endpoint NMAP Scan for Canon Printers</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296483#M596644</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jitendrac_0-1749031188967.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/245942iBB3798414E851889/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jitendrac_0-1749031188967.png" alt="jitendrac_0-1749031188967.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jitendrac_1-1749031279474.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/245943i9F5DEFEF00BC65D3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jitendrac_1-1749031279474.png" alt="jitendrac_1-1749031279474.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296483#M596644</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-06-04T10:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Triggered Endpoint NMAP Scan for Canon Printers</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296897#M596668</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Does a manual NMAP Scan show any open ports on the Canon printers? You mentioned that you'd checked that all nmap ports are permitted FROM the psn to printer - is the return traffic also permitted on any firewalls/ACLs?&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 13:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296897#M596668</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2025-06-05T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Triggered Endpoint NMAP Scan for Canon Printers</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296984#M596674</link>
      <description>&lt;P&gt;Manual NMAP works perfectly as expected. Not sure why it is not triggering an automatic NMAP scan&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect that ISE PSN is not getting&amp;nbsp;IP addresses to MAC binding information via RADIUS&amp;nbsp;(Framed IP Address)&lt;/P&gt;
&lt;P&gt;But I am not sure how to check on ISE if PSN is getting the IP addresses to the MAC binding information via RADIUS&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 17:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296984#M596674</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-06-05T17:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Triggered Endpoint NMAP Scan for Canon Printers</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296985#M596675</link>
      <description>Manual NMAP works perfectly as expected. Not sure why it is not triggering an automatic NMAP scan&lt;BR /&gt;&lt;BR /&gt;I suspect that ISE PSN is not getting IP addresses to MAC binding information via RADIUS (Framed IP Address)&lt;BR /&gt;&lt;BR /&gt;But I am not sure how to check on ISE if PSN is getting the IP addresses to the MAC binding information via RADIUS&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Jun 2025 17:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-triggered-endpoint-nmap-scan-for-canon-printers/m-p/5296985#M596675</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-06-05T17:48:09Z</dc:date>
    </item>
  </channel>
</rss>

