cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3141
Views
0
Helpful
4
Replies

Discover network device from ISE

ignacio.sanchez
Level 1
Level 1

Hi,

 

We use our ISE only as "Devide Admin" and we do not have the "Network Device" in the database, we have the default device enabled.

 

Now we need to apply policies based on the device type. We do not know all the devices that connect to the ISE. Is there a way to add the network devices discovering them automatically from the ISE itself? 

 

I would be appreciated if someone guides me in this regard.

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

Since you have the Default Network Device option configured, you may now look in your logs and reports for your specific network device IP addresses. You will need to spend the time to login to each one and determine the vendor / model / OS version.

Alternatively, you may use the built-in ISE Visibility Setup to scan your network(s) for network devices based on the SNMP Community.

image.png

 

It will scan for your network devices but you must know the SNMP Community string(s):

image.png

 

 

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

If this is used for only Device admin, you can add them put them in discovery mode, and make them according to the requirement to based on the area and profiles

 

you can cattegorise, like switches,. Routers, make a users to access what level access rquired, Full admin or only certain access restrictions and so on.

 

https://community.cisco.com/t5/security-documents/how-to-create-ise-network-access-device-profiles/ta-p/3631103

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for answering so quickly.

 

I need to identify the network device by manufacturer, Cisco, Juniper, Huawei, etc, but I still can't understand how to do it if I can't create the network device and indicate the manufacturer.


The truth is that since I do not know the IP I cannot create it and also in the same network there may be several manufacturers.

You need to do network discovery, get some time read the document it has the process, you do not required to mass network discovery, you can do small subnet.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

thomas
Cisco Employee
Cisco Employee

Since you have the Default Network Device option configured, you may now look in your logs and reports for your specific network device IP addresses. You will need to spend the time to login to each one and determine the vendor / model / OS version.

Alternatively, you may use the built-in ISE Visibility Setup to scan your network(s) for network devices based on the SNMP Community.

image.png

 

It will scan for your network devices but you must know the SNMP Community string(s):

image.png