Profiling based on hostname
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2020 02:47 AM
Hi Experts,
Environment: ISE 2.2
Currently working on a requirement to check a certain encryption software which is only installed on laptops.
So decided to do the posture check using endpoints profiled based on hostnames, as they have already have a hostname naming scheme devices by type, e.g. Laptops, starts with LT and desktops with DT.
So based on this information I have created this profiling policy:
Using this profiling I was able to profile only 127 endpoints... where as there are thousands that I see out there...
While looking at the Context Visibility -> Endpoints, I see that the host name columns is empty...
Does this mean that there are some more probes that are needed to be enabled (already DNS, DHCP, Active Directory and Radius are enabled on all the PSNs).
The other thing that I see is that, when I check the attributes of an endpoint, I see the attribute Systemname has all the host-name of the endpoint...
I am not able to find this attribute to do the profiling though, any idea where this could be found to do the profiling..?
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2020 05:47 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2020 09:54 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2020 10:25 PM
As expected, the device sensor commands are not enabled on every NAD out there.
The question is that, if these commands are enabled on all NADs, will that have any kind of a performance hit? Performance hit on NADs as well as ISE?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2020 09:48 AM
ISE Profiling Services can only run on an ISE appliance configured for the Policy Service node (PSN) persona. ISE scale and performance tables posted to Cisco.com typically list the maximum concurrent sessions supported per PSN and per deployment. However, these values are specific to simultaneous authenticated endpoints, not the total that can be profiled. The total number of endpoints that can be profiled and persisted in the ISE database is much higher.
See here for further detail: https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456
