<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can i disable auto discovery endpoints in ISE ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572303#M509703</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply , after i checked logs , endpoint profile is&amp;nbsp; "unknown" , and everytime PC/NB connect on this environment , the MAC will auto discovery and list on this profile : &lt;/P&gt;&lt;P&gt;&lt;IMG alt="endpoint profile.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/117224_endpoint profile.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/P&gt;&lt;P&gt;may i adjust it to another profile ? like "workstation" or "profiled" , if yes , where is configuration i should modify ?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="endpoint profiled and workstation.jpg" class="jive-image image-2" src="/legacyfs/online/fusion/117225_endpoint profiled and workstation.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 May 2018 06:38:27 GMT</pubDate>
    <dc:creator>sbmc014</dc:creator>
    <dc:date>2018-05-24T06:38:27Z</dc:date>
    <item>
      <title>can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572296#M509685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when i connect my laptop on switch in ISE environment , it will be auto discovery via ISE , and list in Home--&amp;gt;summary--&amp;gt;total endpoints :&lt;/P&gt;&lt;P&gt;&lt;IMG alt="home summary endpoints.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/117209_home summary endpoints.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and put this MAC entry in table :&lt;/P&gt;&lt;P&gt;&lt;IMG alt="put mac in list.jpg" class="jive-image image-2" src="/legacyfs/online/fusion/117210_put mac in list.jpg" style="height: 323px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;When i test 802.1x MACauth via ISE , it always pass due to this MAC existed , any possible i can disable auto discovery endpoints MAC function ? ISE version is 2.4.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 07:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572296#M509685</guid>
      <dc:creator>sbmc014</dc:creator>
      <dc:date>2018-05-23T07:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572297#M509687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you connect to the switch and start radius session ISE will learn the mac address. How you configured the switch&lt;/P&gt;&lt;P&gt;there maybe SNMP configuration too it can learn the mac address from there too.And i think it is necessary all of this for profiling in ISE . And it will not passes if your rules are configured correctly .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572297#M509687</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-05-23T08:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572298#M509688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply , can you give me some advise for how to setting correct configration for MAC auth via&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572298#M509688</guid>
      <dc:creator>sbmc014</dc:creator>
      <dc:date>2018-05-23T08:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572299#M509690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First explain what you want to do ? Show us switch configuration ,show how you create policy ,Authentication and authorization .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572299#M509690</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-05-23T08:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572300#M509693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply , my laptop MAC will be auto discovery in unknown list :&lt;/P&gt;&lt;P&gt;&lt;IMG alt="mac in unknow list.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/117217_mac in unknow list.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/P&gt;&lt;P&gt;and MAC-auth will pass if this MAC existed on this table , and i cannot remove it manually . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;Authentication policy like this :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;&lt;IMG alt="authentication policy.jpg" class="jive-image image-2" src="/legacyfs/online/fusion/117218_authentication policy.jpg" style="width: 620px; height: 332px;" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;authorization policy like this :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;&lt;IMG alt="policy set 20180523.jpg" class="jive-image image-3" src="/legacyfs/online/fusion/117219_policy set 20180523.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;in my opinion , it should some table that i can maintain (keyin MACs that want to authenticated ) , but i cannot find where is it ? Or other configurations i need to adjust ?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; font-style: normal; font-weight: 400; text-align: left; text-indent: 0px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 10:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572300#M509693</guid>
      <dc:creator>sbmc014</dc:creator>
      <dc:date>2018-05-23T10:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572301#M509697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i am pretty sure it hits basic network access ,first of all disconnect your laptop from switch second delete endpoint mac address from context visibility ,than reconnect your laptop to switch and see what happen .I never use this rule and in mine deployment i disable it .I prefer mine rules nor default ones. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 10:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572301#M509697</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-05-23T10:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572302#M509701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot disable the discovery, but if goal is to only allow access to endpoints explicitly assigned to an access group, then you can go to Administration &amp;gt; Identity Management &amp;gt; Groups &amp;gt; Endpoint Identity Groups to add, import (via file/LDAP) MAD addresses into the desired group for policy assignment.&amp;nbsp; You can also use ERS API to update the endpointd and group memberships.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that an given MAC address can belong to only one Endpoint Identity Group at a time, so may be worth looking into Custom Attributes if wish endpoints to belong to multiple classifications for policy assignment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 11:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572302#M509701</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-23T11:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572303#M509703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply , after i checked logs , endpoint profile is&amp;nbsp; "unknown" , and everytime PC/NB connect on this environment , the MAC will auto discovery and list on this profile : &lt;/P&gt;&lt;P&gt;&lt;IMG alt="endpoint profile.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/117224_endpoint profile.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/P&gt;&lt;P&gt;may i adjust it to another profile ? like "workstation" or "profiled" , if yes , where is configuration i should modify ?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="endpoint profiled and workstation.jpg" class="jive-image image-2" src="/legacyfs/online/fusion/117225_endpoint profiled and workstation.jpg" style="width: 620px; height: 349px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 06:38:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572303#M509703</guid>
      <dc:creator>sbmc014</dc:creator>
      <dc:date>2018-05-24T06:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572304#M509705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No you cannot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would recommend if you’re so concerned with this you disable default authorization rule for authenticated that comes on out of box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommendation is to authenticate all but then put an authorization for those you don’t want to allow that redirects them to a portal page with insurrections and gives them limited access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then only authorize with more access those groups you have built manually perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If valid group then permit access full?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 11:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572304#M509705</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-24T11:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: can i disable auto discovery endpoints in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572305#M509707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the absence of an explicit ID group assignment, endpoints will have a default ID Group assigned based on its profile status.&amp;nbsp; If end does not match a known profile, it is assigned a group of Unknown.&amp;nbsp; If it matches a known profile, it is assigned a group of Profiled.&amp;nbsp; If enable profile to "Create Matching Identity Group", it will then be assigned to an Identity Group based on Profile name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case, if wish these endpoints to be granted or denied access, then assign them to a specific ID group and ignore profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 12:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-i-disable-auto-discovery-endpoints-in-ise/m-p/3572305#M509707</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-24T12:43:36Z</dc:date>
    </item>
  </channel>
</rss>

