09-02-2019 07:25 AM
Hey,
i'm trying to profile endpoints with DHCP Probe so i can sort out all "old" Windows 7 PCs. Unfortunatley they are not part of an AD and are only MAB enabled.
With the Standard profiling policies in ISE 2.4 i only get "Windows Workstation" as an profiling result even if its a Win10 oder Win7 endpoint. So i tried to create my own policies and elements.
according to this website https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html
it took these parameters for win7
Windows Vista/7 or Server 2008 | 1,15,3,6,44,46,47,31,33,121,249,43 1,15,3,6,44,46,47,31,33,121,249,43,0,32,176,67 1,15,3,6,44,46,47,31,33,121,249,43,0,176,67 1,15,3,6,44,46,47,31,33,121,249,43,252 1,15,3,6,44,46,47,31,33,121,249,43,195 |
I also see the correct paramters but the custom policies is not used
what am i missing here to get my custom prpfiling policy to work?
thx in advance
Solved! Go to Solution.
09-02-2019 09:20 AM
Increase the certainty factory to 20 and the rule to 20 (or numbers of your choosing above 20). The microsoft workstation profile you are hitting has the same certainty factor and you need your own higher than the base. Similar to how the built in windows 7/8/10 profiles are built.
09-02-2019 09:20 AM
Increase the certainty factory to 20 and the rule to 20 (or numbers of your choosing above 20). The microsoft workstation profile you are hitting has the same certainty factor and you need your own higher than the base. Similar to how the built in windows 7/8/10 profiles are built.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: