cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
442
Views
0
Helpful
1
Replies

DHCP Profiling before sucesfull EAP

piotr.witkowski
Level 1
Level 1

Hi,

 

I am under consideration of enabling profiling along with dot1x in our enviroment. However i have couple of questions regarding how actually profiling would work.

 

  • What are protocols allowed before 802.1x authentication. Are they CDP, STP, EAP? anything else?
    Assuming this correct. How ISE can perform profiling for example DHCP,  if DHCP probes never reach DHCP relay before sucesfully authenticated EAP session?

I understand that DHCP profiling can occurs after EAP session and then via Radius CoA its possible to change VLAN, port state, ACL, etc. 

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee
Profiling doesn’t run before authentication. In order to be able to profile a device you will need to have a valid radius session

I would suggest you look over the profiling design guide to get a better understanding and watch some videos on context visibility profiling in YouTube and following links as well


https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944


https://community.cisco.com/t5/security-documents/ise-community-resources/ta-p/3621621#Visibility

View solution in original post

1 Reply 1

Jason Kunst
Cisco Employee
Cisco Employee
Profiling doesn’t run before authentication. In order to be able to profile a device you will need to have a valid radius session

I would suggest you look over the profiling design guide to get a better understanding and watch some videos on context visibility profiling in YouTube and following links as well


https://community.cisco.com/t5/security-documents/ise-training/ta-p/3619944


https://community.cisco.com/t5/security-documents/ise-community-resources/ta-p/3621621#Visibility