cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2020
Views
0
Helpful
5
Replies

MAB for Printers Profiling

clark white
Level 2
Level 2

Dear,

I have a configured MAB for HP printers which are been profiled as a HP Device by the ISE, I gave them full access in the authorization profile, recently a  guest with HP laptop connected to our network and he was also profiled as a HP Device and he got full access, how I can avoid this situation,

Thanks

5 Replies 5

jan.nielsen
Level 7
Level 7

Well, the obvious answer is don't use profiling as the only condition for access to your network, however if you still wan't to, you need to find a way to make a more precise profiling of your HP printers. You should make sure you have enabled the proper profiling probes in ISE and done the proper NAD configs, to enable proper profiling. The DHCP probe can tell you alot, and in newer switches you can do local dhcp profiling, so you don't have to have helper addresses pointing to ise in every L3 access network

Dear Jan,

however if you still want to, you need to find a way to make a more precise profiling of your HP printers

how ???

I have enabled all the probes except netflow which I have not configured in my network. and for NAD configs  what configuration I have to do ??

But the printers are been detected by radius probe as a HP device becz their model is not available in the ISE, how more granular they can be detected to fall them in them profile which I want. I have other hp printers whose models profile is present in ISE and they are profiled properly for example hp 5500 laserjet XXX .

The DHCP probe can tell you alot, and in newer switches you can do local dhcp profiling

how we can do dhcp profiling.

thanks 

Enabling probes in ISE does not really do much, only for some probes like radius. For a probe like DHCP to work, you need to add the ISE server as a dhcp server in your switches (ip helper-address), so it gets the DHCP packets from the device, this allows ISE to use the data from the dhcp packets to do the profiling. I am not able to say what specifically you should do, as it depends very much on your network infrastucture. You should read this chapter of the trustsec guides to get more information on how to enable these things. : http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf

Dear jan,

I am not able to say what specifically you should do, as it depends very much on your network infrastructure

As you are being expert my question is very simple and from network perspective what exactly you are looking for, ???

I have 12 no's of HP printer some of them are profiled as a HP device and some are profiled according to their model as expected,

Did you read the guide i linked ?