08-28-2017 12:10 PM
A question about how SNMP profiling could be used.
With ISE is it possible to poll, say, a windows laptop or server for an SNMP string and if it based on that result, place the device on the correct VLAN? Or, can SNMP data only be used to profile network access devices?
Thanks!
Solved! Go to Solution.
08-28-2017 03:27 PM
If you have SNMP enabled on any device NMAP should discover that and poll the device using the communities strings you configure in ISE (default is public). You can then use whatever you discover in SNMP in profiling rules. The issue you may have is with the VLAN move. It probably should work with a CoA port bounce, but bouncing the port also disrupts the IP phone on the port if there is one. If you just Reauth you will most likely strand the device as it has an IP on the orginal VLAN and you just moved it to a new VLAN.
Instead of VLAN moves why not DACL assignment?
08-28-2017 03:27 PM
If you have SNMP enabled on any device NMAP should discover that and poll the device using the communities strings you configure in ISE (default is public). You can then use whatever you discover in SNMP in profiling rules. The issue you may have is with the VLAN move. It probably should work with a CoA port bounce, but bouncing the port also disrupts the IP phone on the port if there is one. If you just Reauth you will most likely strand the device as it has an IP on the orginal VLAN and you just moved it to a new VLAN.
Instead of VLAN moves why not DACL assignment?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide