300-715 · Question #244
An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not…
The correct answer is C. Verify that the profiling service is running on the new PSN. If a new Policy Service Node (PSN) in Cisco ISE is not correctly profiling endpoints, the profiling service on that specific PSN must be verified and enabled. Profiling is essential for assigning accurate attributes and matching endpoints to the correct authorization policies.
Question
An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not hitting the correct policies. This was working correctly on the previous PSN. Which action must be taken to ensure the endpoints get identified?
Options
- AVerify that the MnT node is tracking the session.
- BVerify the shared secret used between the switch and the PSN.
- CVerify that the profiling service is running on the new PSN.
- DVerify that the authentication request the PSN is receiving is not malformed.
How the community answered
(60 responses)- A3% (2)
- B8% (5)
- C70% (42)
- D18% (11)
Why each option
If a new Policy Service Node (PSN) in Cisco ISE is not correctly profiling endpoints, the profiling service on that specific PSN must be verified and enabled. Profiling is essential for assigning accurate attributes and matching endpoints to the correct authorization policies.
Verifying the MnT node tracks the session is important for monitoring but doesn't directly solve the issue of the PSN failing to profile endpoints correctly.
If the shared secret between the switch and PSN were incorrect, authentication itself would likely fail, not just profiling. The question states endpoints authenticate, but get wrong profiles.
Profiling services are responsible for collecting endpoint attributes and determining their type, which is critical for assigning the correct policies. When a PSN is replaced, the profiling service may not be enabled by default or could be in a stopped state, leading to endpoints not getting the right profiles.
A malformed authentication request would likely cause authentication failure, not just incorrect profiling after successful authentication.
Concept tested: Cisco ISE PSN persona - Profiling Service
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html#concept_208082520F3E481D886ED12BE7957788
Topics
Community Discussion
No community discussion yet for this question.