<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with telepresence devices on ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719499#M491821</link>
    <description>&lt;P&gt;My Intouch G2 is set up for profiling in ISE via CDP and OUI conditions.&lt;/P&gt;
&lt;P&gt;This profiling policy is part of a logical group, "allowed Telecom"&lt;/P&gt;
&lt;P&gt;The logical grouping, "allowed telecom" for these devices are in a MAB policy set, and receives an authorization profile putting it in the same vlan the voice vlan&amp;nbsp;the port is&amp;nbsp;already assigned.&lt;/P&gt;
&lt;P&gt;In the ISE console, when i look at the endpoint, it states that authorization was successful. Stating that it received this authorization policy and was given an IP in this VLAN. However when i look on the device, which is configured for autoconfig, it states it received an incorrect network config, which shows as empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts on what the issue may be?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;switchport config pre ise&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 42&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input VOICE_POLICY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;switchport config post ise&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 42&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input VOICE_POLICY&lt;/P&gt;</description>
    <pubDate>Thu, 04 Oct 2018 18:55:00 GMT</pubDate>
    <dc:creator>Chape</dc:creator>
    <dc:date>2018-10-04T18:55:00Z</dc:date>
    <item>
      <title>Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719499#M491821</link>
      <description>&lt;P&gt;My Intouch G2 is set up for profiling in ISE via CDP and OUI conditions.&lt;/P&gt;
&lt;P&gt;This profiling policy is part of a logical group, "allowed Telecom"&lt;/P&gt;
&lt;P&gt;The logical grouping, "allowed telecom" for these devices are in a MAB policy set, and receives an authorization profile putting it in the same vlan the voice vlan&amp;nbsp;the port is&amp;nbsp;already assigned.&lt;/P&gt;
&lt;P&gt;In the ISE console, when i look at the endpoint, it states that authorization was successful. Stating that it received this authorization policy and was given an IP in this VLAN. However when i look on the device, which is configured for autoconfig, it states it received an incorrect network config, which shows as empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts on what the issue may be?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;switchport config pre ise&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 42&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input VOICE_POLICY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;switchport config post ise&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 42&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input VOICE_POLICY&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 18:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719499#M491821</guid>
      <dc:creator>Chape</dc:creator>
      <dc:date>2018-10-04T18:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719546#M491842</link>
      <description>&lt;P&gt;You can't assign the port to the same VLAN as the voice VLAN.&amp;nbsp; That is probably what the switch is complaining about.&amp;nbsp; Why can't the Telepresence device use the voice vlan assigned on the port?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 20:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719546#M491842</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-04T20:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719725#M491856</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Can you share please the authorization profu your pushing and the authorization log from ise?</description>
      <pubDate>Fri, 05 Oct 2018 03:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719725#M491856</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-10-05T03:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719885#M491866</link>
      <description>&lt;P&gt;Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cisco phones are running with this same port config and same auth profile and they work perfectly. I never said the&amp;nbsp;switch is complaining about anything. I'm giving it the same vlan it already has. eventually ill throw a different base vlan across all ports with limited access then allow ise to assign the appropriate vlan&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 12:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719885#M491866</guid>
      <dc:creator>Chape</dc:creator>
      <dc:date>2018-10-05T12:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719900#M491876</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Authorization Profile - "Cisco IP Phones"&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Vlan 42 (which is set as an access vlan currently on the switchport as well)&lt;/P&gt;
&lt;P&gt;DACL - "PERMIT_ALL_TRAFFIC" (literally just permit ip any any)&lt;/P&gt;
&lt;P&gt;VOICE Domain Permissions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For authorization log are you referring to the steps in the authentication detail or something else? This again shows it is successful. Right now This authorization policy is in the same policy set&amp;nbsp;as a few other test things so theres some needless user lookups.&amp;nbsp;Would the extended machine authorization cause some kind of timeout? Or you think it might be something else?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;11001Received RADIUS Access-Request&lt;/P&gt;
&lt;P&gt;&amp;nbsp;11017RADIUS created a new session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;11027Detected Host Lookup UseCase (Service-Type = Call Check (10))&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15049Evaluating Policy Group&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15008Evaluating Service Selection Policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15048Queried PIP - DEVICE.Device Type&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15048Queried PIP - Normalised Radius.RadiusFlowType&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15041Evaluating Identity Policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;22072Selected identity source sequence - All_User_ID_Stores&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15013Selected Identity Source - Internal Users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24210Looking up User in Internal Users IDStore - 00:62:EC:8D:80:E5&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24216The user is not found in the internal users identity store&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15013Selected Identity Source - All_AD_Join_Points&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24432Looking up user in Active Directory - All_AD_Join_Points&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24325Resolving identity - 00-62-EC-8D-80-E5&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24313Search for matching accounts at join point - DOMAIN.com&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24318No matching account found in forest - DOMAIN.com&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24322Identity resolution detected no matching account&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24352Identity resolution failed - ERROR_NO_SUCH_USER&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24412User not found in Active Directory - All_AD_Join_Points&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15013Selected Identity Source - Guest Users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24631Looking up User in Internal Guests IDStore&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24633The user is not found in the internal guests identity store&amp;nbsp;&lt;/P&gt;
&lt;P&gt;15013Selected Identity Source - DOMAINAD&amp;nbsp;&lt;/P&gt;
&lt;P&gt;24432Looking up user in Active Directory - DOMAINAD&lt;/P&gt;
&lt;P&gt;24325Resolving identity - 00-62-EC-8D-80-E5&lt;/P&gt;
&lt;P&gt;24313Search for matching accounts at join point - DOMAIN.com&lt;/P&gt;
&lt;P&gt;24318 No matching account found in forest - Domain.com&lt;/P&gt;
&lt;P&gt;24322Identity resolution detected no matching account&lt;/P&gt;
&lt;P&gt;24352Identity resolution failed - ERROR_NO_SUCH_USER&lt;/P&gt;
&lt;P&gt;24412User not found in Active Directory - DOMAINAD&lt;/P&gt;
&lt;P&gt;15013Selected Identity Source - Internal Endpoints&lt;/P&gt;
&lt;P&gt;24209Looking up Endpoint in Internal Endpoints IDStore - 00:62:EC:8D:80:E5&lt;/P&gt;
&lt;P&gt;24211Found Endpoint in Internal Endpoints IDStore&lt;/P&gt;
&lt;P&gt;22037Authentication Passed&lt;/P&gt;
&lt;P&gt;24715ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/P&gt;
&lt;P&gt;15036Evaluating Authorization Policy&lt;/P&gt;
&lt;P&gt;24432Looking up user in Active Directory - DOMAINAD&lt;/P&gt;
&lt;P&gt;24325Resolving identity - 00-62-EC-8D-80-E5&lt;/P&gt;
&lt;P&gt;24313Search for matching accounts at join point - DOMAIN.com&lt;/P&gt;
&lt;P&gt;4318No matching account found in forest -DOMAIN.com&lt;/P&gt;
&lt;P&gt;24322Identity resolution detected no matching account&lt;/P&gt;
&lt;P&gt;24352Identity resolution failed - ERROR_NO_SUCH_USER&lt;/P&gt;
&lt;P&gt;24412User not found in Active Directory - DOMAINAD&lt;/P&gt;
&lt;P&gt;5048Queried PIP - DOMAIN.ExternalGroups&lt;/P&gt;
&lt;P&gt;15048Queried PIP - EndPoints.LogicalProfile&lt;/P&gt;
&lt;P&gt;15016Selected Authorization Profile - Cisco_IP_Phones&lt;/P&gt;
&lt;P&gt;11022Added the dACL specified in the Authorization Profile&lt;/P&gt;
&lt;P&gt;11002Returned RADIUS Access-Accept&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 12:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719900#M491876</guid>
      <dc:creator>Chape</dc:creator>
      <dc:date>2018-10-05T12:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with telepresence devices on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719947#M491927</link>
      <description>&lt;P&gt;So even though i typed above that was my config. It turns out the port wasn't set to voice vlan 42. it was set to access vlan 42. For some reason they configured it differently. After i switched it to voice vlan 42, it worked with ise. So maybe you were on to something. It had something to do with giving it the same vlan back but as voice instead of data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 13:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-telepresence-devices-on-ise/m-p/3719947#M491927</guid>
      <dc:creator>Chape</dc:creator>
      <dc:date>2018-10-05T13:32:42Z</dc:date>
    </item>
  </channel>
</rss>

