cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
187
Views
0
Helpful
7
Replies

ISE - WIFI Profiling Issue

M_alamin
Level 1
Level 1

HI trying to do profiling using MAB over WIFI, i had created initial non-profile auth policy that has ACL from WLC (5508) that allows only DHCP, DNS and IP to ISE PSN, device are hitting this auth profile but keep in unknown state if i hange auth profile to permit access they got profiled successfully which is off course very risky attached is copy of ACL created on WLC knowing my ISE ip is 10.50.3.20 and 10.50.3.30 

 

M_alamin_0-1753209043984.png

 

7 Replies 7

Sorry ypu use profiling mac or using mab authc ?

I need more detail please 

MHM

https://www.cisco.com/c/en/us/products/collateral/wireless/5500-series-wireless-controllers/eos-eol-notice-c51-740221.html

https://cs.co/ise-berg#profiling 

What probes are you using on ISE? Is your feed service up to date? What version of ISE? Do you have RADIUS Profiling enabled on the WLAN?

Ise is 3.3 wlc is 8.5 all profiling probe enable on ise as well as dhcp and http under radius under wlan

Ok so do you actually have DHCP relay configured? Is ISE actually seeing any profiling data? Is the profiling feed service up to date? What patch version of ISE? What exact version of 8.5? You really need to look at getting off of the 5508z

Ok wil look at all of that but can you please advice if the acl is correct or its wrong

I mean I have no idea what you are trying to accomplish with that. Why HTTP? Why a permit all?

He want I think make scan of device connect to his network using ISE profiling probe 

He dont use this profiling for any authc.

@M_alamin 

Check live log' see if there is any dhcp/dns packet receive from wlc.

MHM