01-18-2024 06:26 PM - edited 01-18-2024 07:01 PM
I'm running 3.2 patch 2. I have the NMAP probe enabled (profiling configuration tab) and in General Settings i have "enable profiling service" enabled on the PSN. What I'm not seeing is the PSN actually doing an NMAP scan on a device when it comes online. I'm also letting it sit for sometime and still nothing. The only time i see the NMAP scans doing anything is if i manually kick off a scan. I know this because I'm running a PCAP and when i ping the endpoint from the PSN i see the ICMP packets making it to the client. Is there something else i need to enable? When should i expect to see ISE scan an endpoint?
01-18-2024 08:58 PM
Have you configured an NMAP scan action for your relevant Profiling Policy as per the ISE Profiling Design Guide?
01-19-2024 04:37 AM
01-19-2024 04:59 AM
01-18-2024 09:04 PM
I think you need policy (profiling policy) to trigger NMAP for specific host/subnet
Policy>Policy Elements>Results>Profiling>Network Scan (NMAP) Actions
MHM
01-19-2024 04:38 AM
Morning, yes they are there.
01-19-2024 05:14 AM
sorry I confuse if was set and NMAP not work or now you set it ?
MHM
01-19-2024 05:21 AM
Nope. Looks like there is more to the story. Looks like ISE just doesn't do an NMAP scan even though there is an OS scan. Looks like you need to go into the Profiler Policy list to tell it to do the OS-SCAN when in this case it sees the endpoint as a Microsoft-Workstation. However i'm now getting the attached. Digging into it.
01-19-2024 05:43 AM
Can you more elaborate what condition you use in this profiling policy ?
MHM
01-19-2024 05:46 AM
01-19-2024 05:47 AM
You are welcome friend
MHM
01-19-2024 05:50 AM
You or anyone know of a way to just have ISE do an NMAP scan on everything it finds vs having to go into each of these settings and enable it?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide