11-22-2018 04:48 AM
Hi to All,
i have configured ISE to accept different probes to help our ISE profiling implementation such as SNMP queries, DNS e.t.c. as you can see in the png attached.
One of these probes is DHCP (having already configured SVIs in the appropriate router interfaces where the DHCP servers exist).
However looking in my endpoints i do not see any of them learned by ISE through DHCP probe. There is no ACL between the ISE and the switches , but it seems that the only info i get for my endpoints is the SNMP query that ISE does periodically to the switches.
Is there anything extra i should configure to our switches in order to get dhcp related info in our ISE?
What i have seen in some documents is that the command device sensor should me enabled on the NADs but most of our switches run 15.0(2) which do not support any device sensor command.
Thank you,
Ditter.
Solved! Go to Solution.
11-27-2018 04:16 AM
11-28-2018 04:10 AM
11-22-2018 07:41 AM
11-26-2018 10:54 PM
Thanks, DHCP Snooping is not blocking traffic as trunk ports are DHCP snooping trusted ports.
11-24-2018 07:47 PM
11-26-2018 05:28 AM
You would only need to add the IP helpers if you aren't using device sensor on the switches doing the authentication. If you can run device sensor (requires DHCP snooping to be in place as well), you should be running that on the switches to gather DHCP, CDP and LLDP data.
11-26-2018 11:05 PM
Paul one question for you. Suppose that some of the DHCP clients reside on switch ports that are not configured with any form of authentication (no MAB , no dot1.x).
These clients with no mehtod of authentication, although IP helper address is configured should be able to send to ISE DHCP related info, yes or no?
I suppose the strength of cisco ISE profiling is its ability to profile the clients regardless of the fact that no method of authentication is configured to the switch. Correct or no?
Thanks
Ditter.
11-26-2018 11:09 PM
11-27-2018 02:54 AM
Paul, do i need to have the NAD configured with basic Radius settings even if no authentication occurs?
For example do i need to configure the "radius-server vsa send accounting" command e.t.c. or even these commands are not used for profiling ( i always refer to non authenticated clients).
11-27-2018 04:16 AM
11-28-2018 03:14 AM
thanks paul,
suppose that i would like to have a fresh beginning by deleting the profiling DB of ISE. How can i do that?
I searched the forum but the only purging i see in ISE is the one that runs once a day and purges registered devices and guest endpoints that are older than 30 days.
What i need to do is to see the number of total endpoints devices set to 0.
Thanks,
Ditter.
11-28-2018 04:10 AM
11-28-2018 04:43 AM
11-26-2018 10:54 PM
Thanks Cezak, already done that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide