10-23-2017 12:53 PM
Hi Experts,
Referring to an older discussion: https://cisco.jiveon.com/message/415834?commentID=415834#comment-415834
It's mentioned that detection will work based on dhcp class id change and endpoint ID group change.
There is a customer facing document mentioning 4 parameters:
Configure Anomalous Endpoint Detection and Enforcement on ISE 2.2 - Cisco
The information is a little conflicting and I just wanted clarification on what conditions will anomalous endpoint detection trigger? We know that detection based on dhcp-class-id works. If the other parameters mentioned are incorrect or not considered for detection, i will get the external document edited to reflect the current status of the feature:
Thanks!
Solved! Go to Solution.
10-23-2017 09:33 PM
(3) OS is not a direct attribute used in Anomalous Behavior Detection (ABD) Phase 1. It might be implied from 2 and 4.
10-23-2017 09:33 PM
(3) OS is not a direct attribute used in Anomalous Behavior Detection (ABD) Phase 1. It might be implied from 2 and 4.
10-26-2017 12:19 PM
Thanks Hsing, that makes sense. I spoke to Hariprasad over Jabber and he mentioned as of now the feature requires DHCP-Class-ID to detect the change. In most cases where i speak to customers, we don't expect that a spoofed device will request a DHCP IP, it uses a static IP and spoofs the MAC address. The RADIUS probe MAC OUI won't change and because of lack of other attributes, an OS change or re-profile doesn't trigger and the anomalous detection stays dormant. What are our mandatory conditions for the anomalous detection to trigger is what I'm trying to figure out.
12-15-2017 04:16 PM
See Re: Anomalous client detection behaviour where this topic is covered and specific conditions spelled out. The following TZ article has since been updated as well to more clearly spell out current logic as of ISE 2.3.
Craig
08-08-2019 11:03 AM
Is there an article for public viewing?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide