Given below is additional information related to the manual NMAP scan results: - To detect unknown endpoints, NMAP should be able to learn the IP/MAC binding via NMAP or a supporting SNMP scan. - ISE learns IP/MAC binding of known endpoints via Radius authentication or DHCP profiling. - The IP/MAC bindings are not replicated across PSN nodes in a deployment. Therefore, you must trigger the manual scan from the PSN, which has the IP/MAC binding in its local database (for example, the PSN against which a mac address was last authenticated with). - The NMAP scan results do not display any information related to an endpoint that NMAP had previously scanned, manually or automatically. https://www.cisco.com/c/en/us/td/docs/security/ise/2- 4/admin_guide/reorg/b_endpoint_profiling_2_4.html#concept_57A4A7ADE3DA429A821900C5C BEA8BF0