<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833103#M441804</link>
    <description>&lt;P&gt;Ah I see, you could be correct. I took the ACL configuration from Cisco documentation but didn't understand why the first line allows everything out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would you suggest the ACL be changed?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2019 15:38:59 GMT</pubDate>
    <dc:creator>Jason Weids</dc:creator>
    <dc:date>2019-04-05T15:38:59Z</dc:date>
    <item>
      <title>ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3830736#M441744</link>
      <description>&lt;P&gt;We are trying a PoC to integrate Cisco ISE with Jamf Pro.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have communication with the Jamf Pro server, have developed the authorization profile for unregistered &amp;amp; registered devices &amp;amp; can see that devices are getting the right policy but in the case of unregistered devices the redirect is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone see what is missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Auth Profile&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33414i97FF902A08D8EC95/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Auth Policy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33415i7F1F1F2F8A81A53B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jamf Network Integration&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33416iC60D59B05DFF129C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC ACL&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33417iEE47F9580ADEE742/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture4.PNG" alt="Capture4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3830736#M441744</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2020-02-21T19:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3830826#M441755</link>
      <description>The usual cause is the ACL on the controller isn't configured correctly.  Without seeing the endpoint behavior it is hard to tell for sure.  Is the URL showing up in the mobile device's browser?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;-Tim</description>
      <pubDate>Tue, 02 Apr 2019 16:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3830826#M441755</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-04-02T16:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3831163#M441765</link>
      <description>&lt;P&gt;If you mean the enrol URL then no, it is also possible to browse to any web pages. The ACL I took from the Cisco documentation.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 06:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3831163#M441765</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-03T06:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3832953#M441771</link>
      <description>&lt;P&gt;Is there anyone who can provide some insight on this?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 12:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3832953#M441771</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T12:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833009#M441778</link>
      <description>&lt;P&gt;I usually push back on doing MDM enrollment via ISE, but a few thoughts come to mind:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you are using FlexConnect it is a completely different ACL and process to push that ACL out to the APs.&lt;/LI&gt;
&lt;LI&gt;I doubt there is any explicit proxy in play but that would cause an issue.&lt;/LI&gt;
&lt;LI&gt;Have you confirmed the redirect is getting applied on to the client session?&amp;nbsp; Showing a screen shot of what ISE is sending doesn't really help.&amp;nbsp; You should be looking at the client details on the WLC.&lt;/LI&gt;
&lt;LI&gt;If you don't see the redirect condition on the WLC client side do you have the WLC properly configured for NAC on the advanced tab?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 05 Apr 2019 13:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833009#M441778</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T13:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833063#M441784</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the client seems to be getting the ACL applied from the WLC but the URL doesn't look right it should be the FQDN/enrol&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the URL its getting ISE in the auth profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 715px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33686iEBC8CF8A927D1D58/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833063#M441784</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T14:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833066#M441789</link>
      <description>&lt;P&gt;The client is not FlexConnect?&amp;nbsp; You didn't show the top part of the client details so I couldn't tell if the client was local or flex.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833066#M441789</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T14:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833068#M441791</link>
      <description>&lt;P&gt;Its not flexconnect no.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833068#M441791</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T14:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833071#M441794</link>
      <description>&lt;P&gt;Nevermind, I see hits on your ACL so I assumed the client must be local mode and not FlexConnect.&amp;nbsp; Your ACL looks to only be redirecting traffic to internal web sites.&amp;nbsp; You are testing by going to internal web sites?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833071#M441794</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T14:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; Jamf</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833072#M441798</link>
      <description>&lt;P&gt;No the website is hosted by Jamf but uses our domain name.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833072#M441798</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T14:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833098#M441801</link>
      <description>No that is not what I meant. In order to get redirected you need to hit one of your ACL deny lines.  The only IPs you are redirecting is to internal IPs.  If the user is not surfing to an internal web site they are not going to get redirected to the provisioning web site.  I have a feeling you are surfing to Internet sites and think the setup is not working.</description>
      <pubDate>Fri, 05 Apr 2019 15:33:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833098#M441801</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T15:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833103#M441804</link>
      <description>&lt;P&gt;Ah I see, you could be correct. I took the ACL configuration from Cisco documentation but didn't understand why the first line allows everything out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would you suggest the ACL be changed?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 15:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833103#M441804</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T15:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833125#M441806</link>
      <description>&lt;P&gt;Yes your right. I have tried going to an internal page from the client &amp;amp; I hit rule 8 &amp;amp; I'm redirected but the page fails to load.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The full URL looks like this &amp;amp; fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://myapple.bathspa.ac.uk:8443/mdmportal/gateway?sessionId=ac170170000001065ca7689c&amp;amp;portal=f1260c00-7159-11e7-a355-005056aba474&amp;amp;action=mdm&amp;amp;token=a8dd544b1283a55a4ea8a48ed068b483" target="_blank"&gt;https://myapple.bathspa.ac.uk:8443/mdmportal/gateway?sessionId=ac170170000001065ca7689c&amp;amp;portal=f1260c00-7159-11e7-a355-005056aba474&amp;amp;action=mdm&amp;amp;token=a8dd544b1283a55a4ea8a48ed068b483&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can get to&amp;nbsp;&lt;A href="https://myapple.bathspa.ac.uk:8443/mdmportal/gateway?sessionId=ac170170000001065ca7689c&amp;amp;portal=f1260c00-7159-11e7-a355-005056aba474&amp;amp;action=mdm&amp;amp;token=a8dd544b1283a55a4ea8a48ed068b483" target="_blank"&gt;https://myapple.bathspa.ac.uk&lt;/A&gt;/enrol from the client though.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 15:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833125#M441806</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-05T15:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833134#M441808</link>
      <description>What are you trying to redirect?  The first line is correct.  We only care about the incoming traffic.  If you are trying to redirect any web traffic then you would change the bottom rule to a deny.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Apr 2019 16:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833134#M441808</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T16:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833156#M441810</link>
      <description>It looks like you are incorrectly putting the FQDN of myapple.bathspa.ac.uk in your redirect profile.  You need to bring the traffic to ISE first and make sure your redirect ACL allows traffic to your ISE nodes.  The URL you are seeing is the ISE MDM portal:&lt;BR /&gt;&lt;BR /&gt;mdmportal/gateway?sessionId=ac170170000001065ca7689c&amp;amp;portal=f1260c00-7159-11e7-a355-005056aba474&amp;amp;action=mdm&amp;amp;token=a8dd544b1283a55a4ea8a48ed068b483&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Apr 2019 16:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3833156#M441810</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-05T16:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3834042#M441812</link>
      <description>&lt;P&gt;Thanks Paul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm almost there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I removed the tick in the profile that was inserting the wrong URL.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33842iAA6DA99BA02BA6D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The redirect is now going to the ISE MDM portal.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-08 at 09.10.09.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33843iB8B1571AC8BB94E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-08 at 09.10.09.png" alt="Screen Shot 2019-04-08 at 09.10.09.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After accepting the the Ts &amp;amp; Cs &amp;amp; clicking on enrol it then goes to the Jamf enrolment page which is exactly what we want.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-08 at 09.15.15.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33844i6F75B14FD7370049/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-08 at 09.15.15.png" alt="Screen Shot 2019-04-08 at 09.15.15.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was only when going to an internal page though. It is not redirecting when going to the internet so there is something not right with my ACL.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33845i8DD261E4553F70CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 08:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-jamf/m-p/3834042#M441812</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-04-08T08:26:03Z</dc:date>
    </item>
  </channel>
</rss>

