08-04-2025 02:56 AM - edited 08-04-2025 02:59 AM
Dear Cisco ISE lover,
I have inquiry refer to cisco ISE profiling detection which multi-domain mode on port configuration.
So we have wired with IP Phone and PC these two device is working properly, but in the live log we found another failed authentication with Xerox-Device on the same port which we don't use this xerox device, and also perform failed authentication every 15 minutes and OUI start from 00:00:00 .
While we go to profiling Policy this Xerox-Device is enable by Cisco default.
Question, what is any issue if we disable this Xerox-Device policy?
Thank you,
08-06-2025 03:48 AM
No any VMs.
08-06-2025 08:26 PM
Hi @oum-odom
you are receiving different MACs on your NAD, port 34, with the following format 00:00:00:xx:xx (this is a MAC from Xerox).
Let's isolate the problem:
What is the result ?
Hope this helps !!!
08-06-2025 08:50 PM
Hi @Marcelo Morais
Issue, It happens once Both IP Phone and PC working together.
08-07-2025 03:44 AM
What should we do next?
08-07-2025 03:56 AM
You said that the issue occurs once the PC is connected into the IP Phone?
In that case, does the issue occur when the PC connects directly into the switch (bypassing the phone)?
Do you have the same issue with other PC's and IP Phones on your network or is just this 1 PC? If its just one PC, check drivers applications installed on the PC
hth
Andy
08-08-2025 02:18 AM
Issue happen once the PC connect through IP Phone.
08-07-2025 03:48 AM
Context Visibility > Endpoints <<- see which profiling rule use for known device
MHM
08-08-2025 02:19 AM
Profiling Policy detect is Xerox-Device.
08-08-2025 02:34 AM
Operations > Reports > Endpoints and Users > Endpoint Profiling Summary
please share screenshot and make mark to endpoint with issue
thanks a lot
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide