06-07-2016 04:58 AM - edited 03-10-2019 11:50 PM
Dear,
I have a configured MAB for HP printers which are been profiled as a HP Device by the ISE, I gave them full access in the authorization profile, recently a guest with HP laptop connected to our network and he was also profiled as a HP Device and he got full access, how I can avoid this situation,
Thanks
06-07-2016 08:23 AM
Well, the obvious answer is don't use profiling as the only condition for access to your network, however if you still wan't to, you need to find a way to make a more precise profiling of your HP printers. You should make sure you have enabled the proper profiling probes in ISE and done the proper NAD configs, to enable proper profiling. The DHCP probe can tell you alot, and in newer switches you can do local dhcp profiling, so you don't have to have helper addresses pointing to ise in every L3 access network
06-08-2016 07:53 AM
Dear Jan,
however if you still want to, you need to find a way to make a more precise profiling of your HP printers
how ???
I have enabled all the probes except netflow which I have not configured in my network. and for NAD configs what configuration I have to do ??
But the printers are been detected by radius probe as a HP device becz their model is not available in the ISE, how more granular they can be detected to fall them in them profile which I want. I have other hp printers whose models profile is present in ISE and they are profiled properly for example hp 5500 laserjet XXX .
The DHCP probe can tell you alot, and in newer switches you can do local dhcp profiling
how we can do dhcp profiling.
thanks
06-08-2016 08:07 AM
Enabling probes in ISE does not really do much, only for some probes like radius. For a probe like DHCP to work, you need to add the ISE server as a dhcp server in your switches (ip helper-address), so it gets the DHCP packets from the device, this allows ISE to use the data from the dhcp packets to do the profiling. I am not able to say what specifically you should do, as it depends very much on your network infrastucture. You should read this chapter of the trustsec guides to get more information on how to enable these things. : http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf
06-08-2016 12:20 PM
Dear jan,
I am not able to say what specifically you should do, as it depends very much on your network infrastructure
As you are being expert my question is very simple and from network perspective what exactly you are looking for, ???
I have 12 no's of HP printer some of them are profiled as a HP device and some are profiled according to their model as expected,
06-08-2016 12:47 PM
Did you read the guide i linked ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide