Wired Intelligent Edge

 View Only
Expand all | Collapse all

Missing dhcp fingerprint data on. clearpass

This thread has been viewed 11 times
  • 1.  Missing dhcp fingerprint data on. clearpass

    Posted Jan 16, 2024 05:07 AM

    Hi,

    Have cppm 6.11.5 and 2930 switch firmware WC.16.11.13

    Switch configured to use switch config  device-fingerprints to upload dhcp,http and. lldp info to clearpass.

     Usually this all work fine but  sometimes we dont seem to get dhcp info.

    e.g. Aruba 224 APs configured to use dhcp assigned Ip addresses  ... sh dhcp-snoop bind shows the aps are getting an ip

    clearpass endpoint info shows lldp info for the AP but no dhcp info hence. cnt categorise the device. fix here is to  create custom  fingerprint based upon  mac oui=Aruba and lldp data matches the returned AP text string .... but  would have expected dhcp info to be there.

    e.g. multiple HP deskjet printers using dhcp on same switch, all using dhcp  address assignment.  All get an ip address. On 1 switch can see 3  deskjets with correct fingerprint  but 2 additional ones  have no dhcp fingerprint data ... Cant see anything wrong with  switch config as we're getting. updates for lots of other things.

    Tried a TAC case .... but they spent a log time trying to look for UDP forwarded data .. then. wanted packet capture  data at cppm net interface but  switch uses https to  upload device fingerprint data to cppm (doesnt it?)  so whats the point. of a packet capture.

    Anyone else seen  issues like this?

    A



  • 2.  RE: Missing dhcp fingerprint data on. clearpass

    Posted Jan 16, 2024 07:17 AM

    So just wondering about the https  setting is cppm. The default is 1500 max clients  500 max requests . Switches set  to  upload every 60 secs  which could be pushing it a bit given the size of the estate