05-02-2018 10:03 AM - edited 02-21-2020 10:55 AM
Hello All,
Cisco ISE v2.3
We have the DHCP Probe enabled on the ISE server (*not DHCP SPAN though). And I currently have "ip helper-address <ise-ip>" configured for the User/Data vlan only.
But, we also have a couple of other Vlans that are used for when devices are Non-Compliant, Guest Wi-Fi, BYOD, Voice, etc...
I was wondering if I should be using the "ip helper-address" commands on these other Vlans as well?
Our branch offices use FlexConnect APs, so the different Wi-Fi networks have the Vlans and DHCP Pools configured locally on the Switch in each branch office. So I was wondering if ip helper should be used for those other Vlans as well, *i.e. Guest vlan, BYOD vlan, non-compliant vlan, and maybe even the Voice vlan...?
Thanks in Advance,
Matt
05-02-2018 10:11 AM - edited 05-02-2018 10:18 AM
Hi Matt,
I don't see why not, you'll get more detailed information on the connected endpoint. I guess it also depends on what other profile probes you've enabled e.g snmp/device sensor, if they provide all the information to identify the endpoints on those VLANs then another probe may not be necessary.
HTH
05-02-2018 10:55 AM
05-02-2018 03:00 PM
One other question related to ISE Profiling and Probes.
I just read the following statement:
SNMPQUERY and SNMPTRAP
SNMP is used to query NADs that do not yet support Cisco’s device sensor. After enabling the SNMPQUERY probe, ISE will poll all the SNMP-enabled NADs at the configured polling interval.
NOTE: It is recommended to remove SNMP settings from NADs that support IOS sensor to avoid double work and wasted processing.
Is "IOS Sensor" referring to CDP and LLDP? If so, my switches do support these features, and I have SNMP checked under each of our NAD's settings. So should I disable SNMP in the NAD settings for each switch? And is CDP and LLDP automatically used without needing to enable anything extra in ISE, hey are already enabled within IOS?
Thanks Again,
Matt
05-02-2018 09:12 PM
What version of IOS and on which platfrom? If the switches support device sensor, you should remove any ip forwarders, SNMP and let IOS encapsulate all profiling data in radius packets:
Also, if memory serves me correct ip forwarder does not work on the interface that is also providing DHCP services.
05-03-2018 08:33 AM
05-03-2018 08:44 AM
Hi,
Device Sensor uses the RADIUS Probe (which is enabled as default) and encapsulates the data gathered from cdp, lldp and dhcp in the radius accounting packet. I find device sensor (if the switch supports it) provides enough information, so one less ISE probe to use. You are correct, just disable the SNMP settings defined under the NAD.
With device sensor you can be very granular with what information is sent to ISE in regard to the lldp, cdp attributes. This links here and here have some good examples on how to tweak.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide