04-19-2018 06:43 AM
I have a few deployments where I am using EAP-FAST with chaining via the NAM module and noticing users that are moving from wireless to wired or visa versa are triggering Anomalous Behavior. I believe this is due to the NAS port type change but I am trying to understand why that would be a criteria since the endpoint MAC would be different between those connections. Any help would be appreciated.
Solved! Go to Solution.
04-24-2018 08:32 PM
You are correct that wired and wireless endpoints having different MAC addresses.
I would suggest to engage TAC to debug this or at least you would need to turn DEBUG on profiling and check the log files whenever it happens. It's odd that any normal endpoints would switch profiling policies between printer/phone and workstation.
04-19-2018 09:00 AM
Anomalous detection if enabled, is detected in case of 3 event-
ISE monitors any new information received for existing endpoints and checks if these attributes have changed:
So looks like you are hitting the 1st case
04-19-2018 10:46 AM
Nidhi,
Actually it appears to be the 3rd case but it seems drastic to say that a change from "Microsoft-Workstation" to the more accurate " Windows10-Workstation" would be a trigger.
Has anyone else seen similar behavior?
04-24-2018 08:32 PM
You are correct that wired and wireless endpoints having different MAC addresses.
I would suggest to engage TAC to debug this or at least you would need to turn DEBUG on profiling and check the log files whenever it happens. It's odd that any normal endpoints would switch profiling policies between printer/phone and workstation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide