<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nodo ISE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126453#M1072363</link>
    <description>&lt;P&gt;Sorry I translated your question google. It could be that your ISE nodes are doing NMAP Scans on the clients for profiling? Check your PSN nodes to see if profiling is enabled and whether you have NMAP Scans configured.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 06:01:08 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-07-28T06:01:08Z</dc:date>
    <item>
      <title>Nodo ISE</title>
      <link>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126389#M1072356</link>
      <description>&lt;P&gt;Cordial saludo,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Se ha reportado desde la administración de firewall que hay solicitudes SSH de un nodo ISE a diferentes usuarios de la red (diferentes usurarios en diferentes subredes- este trafico por política es denegado), Hay alguna característica que pueda generar este comportamiento.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 00:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126389#M1072356</guid>
      <dc:creator>alejandro.aguilar</dc:creator>
      <dc:date>2020-07-28T00:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Nodo ISE</title>
      <link>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126453#M1072363</link>
      <description>&lt;P&gt;Sorry I translated your question google. It could be that your ISE nodes are doing NMAP Scans on the clients for profiling? Check your PSN nodes to see if profiling is enabled and whether you have NMAP Scans configured.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 06:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126453#M1072363</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-07-28T06:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Nodo ISE</title>
      <link>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126458#M1072366</link>
      <description>&lt;P&gt;ISE should not be &lt;STRONG&gt;initiating&lt;/STRONG&gt; ssh requests as part of its normal operations.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/InstallGuide27/b_ise_InstallationGuide27/b_ise_InstallationGuide27_chapter_0110.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/InstallGuide27/b_ise_InstallationGuide27/b_ise_InstallationGuide27_chapter_0110.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If an administrator logs into the ISE cli they can initiate ssh manually from there.&lt;/P&gt;
&lt;PRE&gt;ise-latest/admin# show ver

Cisco Application Deployment Engine OS Release: 3.0
ADE-OS Build Version: 3.0.7.071
ADE-OS System Architecture: x86_64

Copyright (c) 2005-2019 by Cisco Systems, Inc.
All rights reserved.
Hostname: ise-latest


Version information of installed applications
---------------------------------------------

Cisco Identity Services Engine
---------------------------------------------
Version      : 2.7.0.356
Build Date   : Thu Nov 14 10:21:59 2019
Install Date : Wed Jul 22 14:27:59 2020

Cisco Identity Services Engine Patch 
---------------------------------------------
Version      : 2
Install Date : Wed Jul 22 16:57:24 2020

ise-latest/admin# &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;ssh ?
  &amp;lt;WORD&amp;gt;  IPv4/IPv6 address or hostname of a remote system (Max Size - 64)&lt;/FONT&gt;&lt;/STRONG&gt;
  delete  Delete the ssh fingerprint for a specific host

ise-latest/admin# ssh&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;EDIT: It could be part of an NMAP profiling scan as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt; mentioned. In that case, there would be multiple destination ports as the ISE node scans the host(s) or subnet(s). You can check if it's enabled by looking at the node under Administration &amp;gt; System&amp;gt; Deployment and then selecting and editing the node:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE NMAP setting.png" style="width: 949px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80278i1AA43A691E82F4CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE NMAP setting.png" alt="ISE NMAP setting.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 06:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nodo-ise/m-p/4126458#M1072366</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-28T06:15:25Z</dc:date>
    </item>
  </channel>
</rss>

