An engineer wants to automatically assign endpoints that have a specific OUI into a new endpoint group. Which probe must be enabled for this type of profiling to work?
I agree. NMAP scan is based on IP, any information collected during scan will be discarded if MAC-IP binding doesn't exist
According to ISE profile design guide, "The dhcp-client-identifier typically provides the MAC address, which in turn provides the vendor OUI information through correlation from the MAC Address-OUI mapping table." under Procedure 25 Verify DHCP Probe Data
https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-2096149162
in addition to Jeeves69, It is option 60, not 61
https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-2725.pdf
Vendor / OS information can be gathered from dhcp-class-identifier (60)
DHCP parameter request list and DHCP class ID can be used for platform and model.
The dhcp-client-identifier typically provides the MAC address, which in turn provides the vendor OUI information through correlation from the MAC Address-OUI mapping table.
The dhcp-class-identifier often provides a unique platform-specific attribute and in some cases provides a detailed description of the connected endpoint - in this example, MSFT 5.0 which is the value assigned to Microsoft Windows workstations.
https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456
The answer is SNMP. It will work and can pull ARP tables from the network devices. In fact, page 28 in the ISE Profiling guide recommends it if Radius or DHCP probes can't be effective.
An NMAP scan cannot get a MAC address. If it is on the same subnet, then it would pull the MAC from the ARP table which would then be effective. That's a big IF
DHCP would missing static devices as mentioned.
A Netflow probe with additional attributes of SRC_MAC and DST_MAC should also be able to work for this situation if placed properly within the networks but I'm going with SNMP as that is what is recommended in the guide.
Explanation:
To automatically assign endpoints with a specific Organizationally Unique Identifier (OUI) into a new endpoint group, Cisco ISE needs to identify the MAC addresses of those endpoints.
The DHCP probe extracts MAC addresses from DHCP request packets, allowing Cisco ISE to determine the OUI (first 24 bits of the MAC address) and categorize devices accordingly.
Why not the other options?
A. SNMP – Used for network device discovery, but not effective for identifying endpoint MAC addresses dynamically.
B. NMAP – Performs active scanning but does not focus on OUI-based profiling.
D. NetFlow – Provides traffic flow analysis, but does not extract MAC addresses from endpoint traffic.
Correcting myself from my answer below. According to "Probe Selection Best Practices" in the ISE Profiling Designing Guide, from the official Cisco documentation, it's SNMP.
I vote for C.
As many before have said, the DHCP probe in Cisco ISE can capture information from DHCP requests, including the MAC address of the endpoint. The OUI is part of the MAC address and can be used to profile and categorize endpoints into specific groups based on this information.
DHCP. This is the most used function for ISE to learn about endpoints. Since it can learn about them even if the endpoints are not in a 802.1x enabled port. NMAP is a manually/triggered. Its teoretic that some clients use static IP. Most devices use dhcp
Why not D? Check profiling probe using net flow v9 ... also dhcp on security perspective uses ip to mac binding doesn't mean it is used as a probe to get mac details..
Probe SNMP:
Key profiling attributes:
· MAC Address/OUI
- CDP/LLDP
- ARP tables
Common Endpoint Profiling Use Cases
See RADIUS probe for MAC info.
Valuable for any vendor that uses CDP/LLDP. For example,
Cisco IP phones, cameras, access points, appliances.
Polling of device ARP tables populates ISE MAC-to-IP bindings.
https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456
CTRL + F to the setion: "Probe Selection Best Practices"
NMAP scans for open ports and OS detection, how do you get MAC address in NMAP scans over L3? you can configure SNMP probes to start profiling and populating endpoints before enforcing MAB/802.1X IN ISE. I have done this a few times.
This section is not available anymore. Please use the main Exam Page.350-701 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Jeeves69
Highly Voted 4 years, 1 month agosemi1750
3 years, 1 month agosemi1750
2 years, 12 months agoPremium_Pils
8 months, 3 weeks ago044f2fc
1 year ago044f2fc
1 year agonomanlands
Highly Voted 2 years, 9 months agomadboy2
Most Recent 1 month, 1 week agoBasuso
5 months, 3 weeks agoBasuso
5 months, 3 weeks agokloug
6 months, 1 week agoluismg
7 months, 2 weeks agoPremium_Pils
8 months, 3 weeks agoKorndal
10 months agoRemiK
10 months, 3 weeks agoRododendron2
11 months agoc66bc39
11 months ago044f2fc
1 year ago044f2fc
1 year ago044f2fc
1 year agosquirrelzzz
1 year, 1 month agonekkrokvlt
1 year, 7 months agoGoldFree
1 year, 8 months agoF0rtyx40
1 year, 9 months ago