cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
6951
Views
15
Helpful
4
Replies

Cisco ISE performing NMAP scans at regular intervals.

Folks,

I understand that the Cisco ISE PSN's should do some NMAP scans on the network at regular intervals.

However, I do not see that to be the case.

 

e.g. we have few devices where the OS and ports detected in NMAP scan do not show up.

However, if we do a manual scan to this device from the ISE it shows up correctly.

 

We have all the nodes configured to NMAP in the "Profiling Configuration".

It reads "The NMAP probe will scan endpoints for open ports and OS."

 

Our challenge is where are we going wrong and why the results show up only after a manual scan.

 

Any suggestions? 

 

 

Regards,

N!

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

what ISE version, how is your autoscan profile looks like compare to Manual scan

 

check some reference guide :

https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design

https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1651437215

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Balaji,

Thanks! The ISE version is 3.0.

 

When you say autoscan, I understand you are referring to NMAP Scan Actions under "Policy Elements".

If yes, there is no difference in the autoscan and the manual scan I did.

 

Regards.

andrewswanson
Level 7
Level 7

Hi

See this previous post on how/when ISE performs nmap scans

 

https://community.cisco.com/t5/network-access-control/nmap-scan-questions/td-p/3776212

 

NMAP can be triggered in the following cases:

  • Manual NMAP scan
  • Automatically when endpoint discovered and profile set to Unknown
  • Automatically by matching a profile and one of the matching conditions has action to trigger NMAP. The NMAP scan type is defined under the NMAP Scan Actions (under Policy > Policy Elements > Results > Profiling > NMAP Scan Actions).

 

hth
Andy

hslai
Cisco Employee
Cisco Employee

ISE needs the mapping of the IP address to the MAC address in order to update the NMAP results to the endpoint.