top of page

Profiling in Cisco ISE

Updated: Jan 21



We can discuss Profiling Probes in Cisco ISE --

 

ISE has several methods of detecting what type of device isconnecting to the network, mostly we are using a common method to identify device.

 

 Network Scan (NMAP)  --

Will run an intrusive scan on the endpoint. Typically used in conjunction withother probes and only when necessary. 


• DNS 

Checks DNS records for additional information.


SNMPQUERY/SNMPTRAP 

Gathers information from SNMP. This is typically used to help identifynetworking equipment. 


Active Directory 

Queries AD for additional endpoint information for AD joined devices.

 

 pxGrid 

 Used with the Cisco Industrial Network Director (not covered in this course

 

 

ISE comes with a database of endpoint attributes which gets updated  frequently.

 

• Each profile rule is assigned a numerical value, if matched.


• The matched rules are added together to determine a Certainty Factor.


• If the added rules exceed the “Minimum Certainty Factor”, the  overall profile is matched.

 

 

We can use one example to understand profiling -

we can create one profile in ISE profile named “Switch”

 


• When a device first attaches to the network, ISE does not know what it is yet. Seconds later, ISE receives the profiling data and we must configure which action we want ISE to take. This can be set globally or under each profile:

 

•Take No Action

 

The device will remain “unknown” until it does a re-authentication naturally.


Port Bounce

   ISE will instruct the network access device to bounce the connection. The device will re-authenticate, but now we have the profiling data and it will match whichever profile.


 Reauth

        ISE will force the endpoint to re-authenticate (faster than port bounce)

2 views0 comments

Recent Posts

See All

ISE BYOD: Dual vs Single SSID Onboarding

In general it is recommended to minimize number of ' SSIDs. Also, if the guest access is using hotspot access then single-SSID BYOD is...

Unable to login on cisco ISE though GUI

We can troubleshoot the issue about Unable to login on ISE through GUI . This is a very common issue. If you are not able to login on ISE...

Cisco ise lab free provided by cisco

Cisco ISE lab free online -- Now you can get Cisco ISE lab free that's provided by Cisco - step 1- login into the below URL also make...

TAgs

Categorys

bottom of page