<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to differentiate between  iPad &amp; other apple devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009753#M24173</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;I have a condition where i have to match a corporate AD group who will access internet on corporate provided IPAD only ( not even their iphone),&lt;/P&gt;
&lt;P&gt;how i can differentiate between ipad and iphone with a specific AD group access.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:25:33 GMT</pubDate>
    <dc:creator>clark white</dc:creator>
    <dc:date>2019-03-11T07:25:33Z</dc:date>
    <item>
      <title>Unable to differentiate between  iPad &amp; other apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009753#M24173</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;I have a condition where i have to match a corporate AD group who will access internet on corporate provided IPAD only ( not even their iphone),&lt;/P&gt;
&lt;P&gt;how i can differentiate between ipad and iphone with a specific AD group access.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009753#M24173</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2019-03-11T07:25:33Z</dc:date>
    </item>
    <item>
      <title>Are use using profiling in</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009754#M24174</link>
      <description>&lt;P&gt;Are use using profiling in your policies? That allows you to differentiate using multiple attributes, including the Safari User Agent which identifies an iPad as the source device type.&lt;/P&gt;
&lt;P&gt;See the following sources for some examples:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/document/128386/profiling-cisco-ise&lt;/P&gt;
&lt;P&gt;https://communities.cisco.com/docs/DOC-68156&lt;/P&gt;
&lt;P&gt;If you want furhter security, you could issue device certificates to the corporate iPads and check the certificate in your policy.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 04:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009754#M24174</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-02-02T04:20:56Z</dc:date>
    </item>
    <item>
      <title>Dear Marvin,</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009755#M24177</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;thanks for your reply,&lt;/P&gt;
&lt;P&gt;safari user agent can come with iphones also my goal is to restrict ipad on the specific ssid for corporate AD group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just wanted to make sure, we have an internal CA &amp;nbsp;can we use the internal CA certificates for the ipad to identify as a corporate ipads. this will help us to segregate IPads from iphones and other apple devices.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 22:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009755#M24177</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2017-02-04T22:06:42Z</dc:date>
    </item>
    <item>
      <title>You can use a variety of</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009756#M24179</link>
      <description>&lt;P&gt;You can use a variety of attributes in profiling - not just br owner user agent but also things like DHCP discover packets, MAC addresses etc. In my experience ISE dcistinguishes between iPads and iPhones quite reliably.&lt;/P&gt;
&lt;P&gt;Certificates are an even more reliable method. They can certainly be used in your policy set to distinguish the device type.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2017 02:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-differentiate-between-ipad-other-apple-devices/m-p/3009756#M24179</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-02-05T02:54:45Z</dc:date>
    </item>
  </channel>
</rss>

