49-116
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 49 Configuring 802.1X Port-Based Authentication
Configuring Device Sensor
Figure 19
Device Sensor and Clients
Client notifications and accounting messages that contain profiling data and other session-related data are generated and sent
to the internal clients and the ISE. By default, client notifications and accounting events are generated only when an incoming
packet includes a Type-Length-Value (TLV) that has not previously been received within a given access session. You can enable
client notifications and accounting events for TLV changes; that is, when a previously received TLV is received with a different
value.
Device Sensor port security protects a switch from consuming memory and crashing during deliberate or unintentional
denial-of-service (DoS)-type attacks. Device Sensor limits the maximum number of device monitoring sessions to 32 per port.
While hosts are inactive, the age session limit is 12 hours.
MSP-IOS Sensor Device Classifier Interaction
Note
To enable MSP, you must configure the
profile flow
command. Once done, when SIP, H323, or mDNS
traffic are present, appropriate (SIP, H323, or mDNS) TLV notifications are sent to the IOS sensor.
MSP (Media Service Proxy) offers bandwidth reservation for audio or video flows and Metadata services to 3rd-party
endpoints. To offer and install Media services, MSP must identify flow attributes and device details. MSP device identification
requires automatic identification of various media end points in the network, thereby avoiding any change to the installed end
point base. To offer MSP device discovery services, MSP leverages current IOS sensor capability for device classification.
(Starting with Release IOS XE 3.3.0SG and IOS 15.1(1)SG, IOS sensor can be used to perform device identification. MSP uses
the same functionality with the addition of SIP, H323, and Multicast DNS (mDNS) protocols.) Starting with Release IOS XE
3.4.0SG and IOS 15.1(2)SG, MSP offers Media services to two kinds of media endpoints: IP Surveillance Cameras and
Video-Conferencing Endpoints. Surveillance cameras are identified using mDNS protocol whereas
Video-conference-Endpoints are identified using SIP and H.323 protocols.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...