09-02-2019 07:25 AM
Hey,
i'm trying to profile endpoints with DHCP Probe so i can sort out all "old" Windows 7 PCs. Unfortunatley they are not part of an AD and are only MAB enabled.
With the Standard profiling policies in ISE 2.4 i only get "Windows Workstation" as an profiling result even if its a Win10 oder Win7 endpoint. So i tried to create my own policies and elements.
according to this website https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html
it took these parameters for win7
Windows Vista/7 or Server 2008 | 1,15,3,6,44,46,47,31,33,121,249,43 1,15,3,6,44,46,47,31,33,121,249,43,0,32,176,67 1,15,3,6,44,46,47,31,33,121,249,43,0,176,67 1,15,3,6,44,46,47,31,33,121,249,43,252 1,15,3,6,44,46,47,31,33,121,249,43,195 |
I also see the correct paramters but the custom policies is not used
what am i missing here to get my custom prpfiling policy to work?
thx in advance
Solved! Go to Solution.
09-02-2019 09:20 AM
Increase the certainty factory to 20 and the rule to 20 (or numbers of your choosing above 20). The microsoft workstation profile you are hitting has the same certainty factor and you need your own higher than the base. Similar to how the built in windows 7/8/10 profiles are built.
09-02-2019 09:20 AM
Increase the certainty factory to 20 and the rule to 20 (or numbers of your choosing above 20). The microsoft workstation profile you are hitting has the same certainty factor and you need your own higher than the base. Similar to how the built in windows 7/8/10 profiles are built.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide