01-07-2020 05:45 AM - edited 01-07-2020 06:20 AM
we have the ISE 2.6 with Profiling license, after we update one client system from win7 to win10, in ISE we can just see the old information(win7), how can I override the old attibutes? I tried with nmap mauel scan, but after scan the ISE show me win7... But the system is already updated to win10...
anyone have a good idea?
regards
Robin
Solved! Go to Solution.
01-07-2020 01:15 PM
01-07-2020 02:12 PM
Hi Robin,
To answer your question, there is no way to schedule a weekly manual NMAP scan. Triggered NMAP scans only take place if the Exception Action is configured in the Profiling Policies.
Keep in mind that discovering the Windows OS version via NMAP requires the use of the SMB Discovery scan. This is typically not very useful because SMB ports would normally be blocked somewhere in the path between the PSN and the end PC or limited by the host firewall.
There is no difference between the DHCP Class Identifier for Windows 7 and 10 (both are 'MSFT 5.0'), so the AD Probe provides the best method for profiling the OS on AD-joined computers. If you're not using the AD Probe, you should consider enabling it. If you're using the AD Probe, but ISE is receiving incorrect OS info from AD, you might need to investigate AD.
Cheers,
Greg
01-07-2020 05:59 AM
Moved the discussion to ISE Forum for better visibility.
Depending on your profiler probes that are active, you would normally get new information and overwrite any previous values when the probe receives it.
You could also remove the endpoint from context visibility to "force" a new profile to be discerned the next time the device connects.
01-07-2020 06:08 AM
01-07-2020 02:12 PM
Hi Robin,
To answer your question, there is no way to schedule a weekly manual NMAP scan. Triggered NMAP scans only take place if the Exception Action is configured in the Profiling Policies.
Keep in mind that discovering the Windows OS version via NMAP requires the use of the SMB Discovery scan. This is typically not very useful because SMB ports would normally be blocked somewhere in the path between the PSN and the end PC or limited by the host firewall.
There is no difference between the DHCP Class Identifier for Windows 7 and 10 (both are 'MSFT 5.0'), so the AD Probe provides the best method for profiling the OS on AD-joined computers. If you're not using the AD Probe, you should consider enabling it. If you're using the AD Probe, but ISE is receiving incorrect OS info from AD, you might need to investigate AD.
Cheers,
Greg
01-14-2020 07:23 AM
Hi Greg,
thanks for your answer. we have already actived the AD Probe. we will check the AD.
Regards
Robin
01-07-2020 01:15 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide