<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD device stuck in pending state and device removal in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723751#M507012</link>
    <description>&lt;P&gt;Also is there a bug ID for the pending cosmetic issue?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Oct 2018 15:52:52 GMT</pubDate>
    <dc:creator>Madura Malwatte</dc:creator>
    <dc:date>2018-10-11T15:52:52Z</dc:date>
    <item>
      <title>BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723574#M506991</link>
      <description>&lt;P&gt;I have this issue and some unexpected behaviour with byod.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First when I go through the byod registration processes everything seems well and after I complete registration, I hit the correct authz policy (byod registered + compliant), I do the temporal agent install and posture check as well. My device gets full access as expected. However if in the mydevices portal the device is always in pending state. It never transitions to registered state, even though device has done CoA to the correct authz policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20181011_175135.jpg" style="width: 462px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20120i68D6EEF80B951F2A/image-dimensions/462x254?v=v2" width="462" height="254" role="button" title="20181011_175135.jpg" alt="20181011_175135.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the question is how do I go about removing a device? the only option I have is "delete", when I do this, device is deleted, but the native dot1x settings remain on the device (which was configured by the&amp;nbsp;windwos sp wizard), so when&amp;nbsp;the device connects to the network again, im getting pushed into my dot1x policy (obviously because the dot1x&amp;nbsp;is still enabled on the device) and then hitting the default policy which takes me to a dead end. The device can never hit the portal and try to register itself again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20181011_180256.jpg" style="width: 315px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20123iDB5AE05D59C2DF91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20181011_180256.jpg" alt="20181011_180256.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20181011_175220.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20125i30EBF83BE64F408E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20181011_175220.jpg" alt="20181011_175220.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess trying to "delete" a byod device is not the correct way to go? Would doing "unenroll" actually remove the dot1x settings from the device, so when it tried to connect to the network will hit my mab policy and then get the web auth redirect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Questions:&lt;/P&gt;
&lt;P&gt;1. Why is the device stuck in "pending" state and never transition to "registered" even though the registration process seems to have worked correctly?&lt;/P&gt;
&lt;P&gt;2. How can I get the device to hit the portal and go through registration again if it is deleted or removed&amp;nbsp;as a byod registered device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 12:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723574#M506991</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-10-11T12:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723591#M506997</link>
      <description>Please review the guide on proper policies&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pending state is a cosmetic issue and doesn’t affect operation&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Oct 2018 13:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723591#M506997</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-11T13:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723636#M507003</link>
      <description>&lt;P&gt;Thanks Jason, but I have been through this guide. I'm testing wired on-boarding by the way. I&amp;nbsp;had waited a few hours and still the device was in pending state. (it&amp;nbsp;mentions 20 minutes to transition in the guide).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also there is no mention on correct removal process of registered device so it can re-register.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 14:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723636#M507003</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-10-11T14:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723675#M507006</link>
      <description>Pending is cosmetic issue unfortunately&lt;BR /&gt;&lt;BR /&gt;Please remember this solution is not an EMM/MDM management product. It’s a way to onboard personal devices that you have no controls over. Because of this there is no way to remove through ISE the supplicant and certificate provisioned on the device.  This is a manual process of removing the supplicant settings using that cert and is different depending on the device type and OS version.&lt;BR /&gt;&lt;BR /&gt;If you remove an endpoint from ISE BYODRegistered state or group then you can force them through authorization.&lt;BR /&gt;This will also force them through if you remove the certificate from the endpoint or revoked the certificate as its not valid anymore&lt;BR /&gt;PEAP &amp;gt; TLS network&lt;BR /&gt;Example authorization profiles&lt;BR /&gt;if BYODRegistered and EAP-TLS certificate valid then permit access&lt;BR /&gt;if PEAP then redirect to onboarding flow&lt;BR /&gt;&lt;BR /&gt;OPEN &amp;gt; TLS network&lt;BR /&gt;if BYODRegistered and EAP-TLS certificate valid then permit access&lt;BR /&gt;otherwise redirect to guest portal&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Oct 2018 14:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723675#M507006</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-11T14:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723746#M507009</link>
      <description>Hi Jason,&lt;BR /&gt;&lt;BR /&gt;Thanks for confirming the behaviour. So seems in pending state the unenroll&lt;BR /&gt;and unregister options are not available?&lt;BR /&gt;&lt;BR /&gt;Great, this is what I was looking for, a way to force through&lt;BR /&gt;authorization. I'll give it a go!&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723746#M507009</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-10-11T15:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723750#M507011</link>
      <description>There is no unenroll or unregister options, you can either mark a device as lost or stolen correct? Are you talking about integrating with MDM state as well?&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723750#M507011</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-11T15:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723751#M507012</link>
      <description>&lt;P&gt;Also is there a bug ID for the pending cosmetic issue?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723751#M507012</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-10-11T15:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723753#M507013</link>
      <description>Yes there are several I believe &lt;BR /&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3723753#M507013</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-11T15:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD device stuck in pending state and device removal</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3997451#M507015</link>
      <description>&lt;P&gt;What is BugID?&amp;nbsp; I can't find it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jim&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 20:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-device-stuck-in-pending-state-and-device-removal/m-p/3997451#M507015</guid>
      <dc:creator>jdurkin</dc:creator>
      <dc:date>2019-12-11T20:49:23Z</dc:date>
    </item>
  </channel>
</rss>

