<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE profiling an IP range in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329080#M598095</link>
    <description>&lt;P&gt;Why is that your requirement at all? What information are you not getting from Device Sensor?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Sep 2025 19:54:58 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2025-09-10T19:54:58Z</dc:date>
    <item>
      <title>ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5328394#M598074</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a requirement to profile devices based on IP range.&amp;nbsp; This is easy if my subnets are on octet boundries.&amp;nbsp; So I can match the 10.10.10.0/24 subnet with&amp;nbsp;startswith 10.10.10 and that works fine.&lt;/P&gt;&lt;P&gt;However if my subnet is, for example, 10.10.0.0/20 I need to match 10.10.0.0 to 10.10.15.255 and I would like to match this with a startswith statement.&amp;nbsp; Is there any way I can insert a range of 0-15 in the startswith field or is there any other way I could do this?&lt;/P&gt;&lt;P&gt;Thanks, Kev.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 09:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5328394#M598074</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2025-09-09T09:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5328427#M598076</link>
      <description>&lt;P&gt;i do not believe that have option as per i know, its wish list, but not a good idea&amp;nbsp; have 3rd octet range.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 11:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5328427#M598076</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-09T11:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329075#M598092</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191315"&gt;@KevinR99&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a requirement to profile devices based on IP range.&amp;nbsp; This is easy if my subnets are on octet boundries.&amp;nbsp; So I can match the 10.10.10.0/24 subnet with&amp;nbsp;startswith 10.10.10 and that works fine.&lt;/P&gt;&lt;P&gt;However if my subnet is, for example, 10.10.0.0/20 I need to match 10.10.0.0 to 10.10.15.255 and I would like to match this with a startswith statement.&amp;nbsp; Is there any way I can insert a range of 0-15 in the startswith field or is there any other way I could do this?&amp;nbsp;&lt;FONT color="#FFFFFF"&gt;&lt;A href="http://y999gameapp.pk/" target="_self"&gt;y999&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Thanks, Kev.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I see what you’re running into. A /20 subnet like 10.10.0.0/20 spans multiple /24 networks (10.10.0.0/24 through 10.10.15.0/24). A simple startswith string match works fine for octet boundaries (like /24), but it won’t handle ranges inside an octet (like 0–15) because startswith is just a string check — it can’t do numeric ranges.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 19:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329075#M598092</guid>
      <dc:creator>andrewchawen</dc:creator>
      <dc:date>2025-09-26T19:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329080#M598095</link>
      <description>&lt;P&gt;Why is that your requirement at all? What information are you not getting from Device Sensor?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 19:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329080#M598095</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-09-10T19:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329360#M598138</link>
      <description>&lt;P&gt;My problem is I have 10 floors in my buiding.&amp;nbsp; Each has a different subnet for door entry systems and those have static IP's applied.&amp;nbsp; So I want to profile them based on the static IP and place them in an endpoint group specific to their IP subnet. I can't profile on MAC OUI or any other info like that because they are all the same type of device.&amp;nbsp; I will then use the endpoint group in a mab policy to authenticate the port and place it in the appropriate vlan.&amp;nbsp; So, if my subnets are not on octet boundries I cannot match with startswith.&amp;nbsp; If my subnet is 10.10.0.0/20 I would need to match on starts with 10.10.0. up to 10.10.15.&amp;nbsp; I could create 16 profiling rules but that's getting a bit labour intensive especially as the subnets get bigger.&lt;/P&gt;&lt;P&gt;I had hoped I could apply a regex expression to match 0-15 in the 3rd octet but I can't find a way to do that.&lt;/P&gt;&lt;P&gt;Kev.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 15:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329360#M598138</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2025-09-11T15:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling an IP range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329368#M598141</link>
      <description>&lt;P&gt;Got it. Are those ports exposed to the general user population? Or are they protected in a locked area? Have you considered removing the ISE authentication commands from those ports entirely and just manually configuring the VLANs?&lt;/P&gt;
&lt;P&gt;For static IP devices like this, I typically recommend my customers use a SPAN-based profiler like Ordr, Armis, or Cisco Endpoint Analytics.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 16:26:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-an-ip-range/m-p/5329368#M598141</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-09-11T16:26:23Z</dc:date>
    </item>
  </channel>
</rss>

