<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On-prem MDM with unknown MAC Address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488072#M520625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using Casper as well, Chad from Cisco opened the case based on the TAC case we've opened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JAMF suggesting us to install Any connect ISE compliance module to resolve the wired deployment issue. Looking further into it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Oct 2017 18:03:01 GMT</pubDate>
    <dc:creator>pkinjaram</dc:creator>
    <dc:date>2017-10-24T18:03:01Z</dc:date>
    <item>
      <title>On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488066#M520615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to get some feedback on what's beginning to be a more common scenario, especially with the new release of MacBooks requiring the use of dongles exclusively for wired networks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Consider this scenario:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;New MacBook with only Wifi registers against an MDM server. The MDM server records the MAC address, the serial number, version, etc. &lt;/LI&gt;&lt;LI&gt;Users takes endpoint to work, performs a wireless authentication, and since the Wifi mac is stored in the MDM server ISE can look up the endpoint and user gets full network access.&lt;/LI&gt;&lt;LI&gt;User transitions to ethernet, but this requires a dongle. ISE attempts to do the lookup, but since the endpoint was registered without the dongle present, MDM cannot locate this specific endpoint and the endpoints registration/compliance statuses cannot be pulled. &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;At this point, everything appears to be functioning as expected, but there has to be a better solution than forcing endpoints to re-enroll with MDM while their specific dongle is plugged in. Is there a solution or talks in progress to address this specific use cases with Apple (or any) endpoints that require dongles for network access? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remember facing a similar issue with VPN authentications when Apple/Google started hiding/randomizing the mac address, and as&amp;nbsp; a result we now the queries with the UDID. But since these are on-prem authentications failing, it's impossible to pull these extra values from a dot1x/mab authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 19:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488066#M520615</guid>
      <dc:creator>chbuey</dc:creator>
      <dc:date>2017-10-20T19:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488067#M520616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chad, &lt;/P&gt;&lt;P&gt;I will be researching on this. Will reply back on this post soon . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Oct 2017 16:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488067#M520616</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-10-21T16:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488068#M520617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running into the exact same issue with my deployment.&amp;nbsp; Macbooks + tunderbolt dongle results in a failed MDM lookup everytime.&amp;nbsp; We just gave up on wired MDM enforcement.&amp;nbsp; Pretty sad this was overlooked on the design side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Oct 2017 17:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488068#M520617</guid>
      <dc:creator>Network Engineering</dc:creator>
      <dc:date>2017-10-21T17:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488069#M520618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of mac management software are you using in your environment?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 15:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488069#M520618</guid>
      <dc:creator>pkinjaram</dc:creator>
      <dc:date>2017-10-24T15:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488070#M520619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 15:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488070#M520619</guid>
      <dc:creator>pkinjaram</dc:creator>
      <dc:date>2017-10-24T15:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488071#M520622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm using Casper Suite (JAMF).&amp;nbsp; I suspect the original poster is as well as it's the most common Mac management software.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 16:27:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488071#M520622</guid>
      <dc:creator>Network Engineering</dc:creator>
      <dc:date>2017-10-24T16:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488072#M520625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using Casper as well, Chad from Cisco opened the case based on the TAC case we've opened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JAMF suggesting us to install Any connect ISE compliance module to resolve the wired deployment issue. Looking further into it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 18:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488072#M520625</guid>
      <dc:creator>pkinjaram</dc:creator>
      <dc:date>2017-10-24T18:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488073#M520628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the ise-compliance module installed as that is required for posture which is also required in our environment.&amp;nbsp; The issue we have is not with posture, it's with MDM registration enforcement.&amp;nbsp; We enforce MDM registration with JAMF for Macbooks on our network.&amp;nbsp; The way MDM registration enforcement works between ISE and JAMF is that ISE will query JAMF via its API integration for the MAC address of the connecting endpoint.&amp;nbsp; Modern macbooks don't have wired ports thus every Macbook uses a dongle of some sort to connect.&amp;nbsp; The Macbook dongles do not exist in MDM resulting in the MDM returning not-registered for the device.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our users are highly mobile and do not have static desks or static dongles.&amp;nbsp; We've had to disable MDM registration enforcement for wired.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 18:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488073#M520628</guid>
      <dc:creator>Network Engineering</dc:creator>
      <dc:date>2017-10-24T18:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488074#M520631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They don’t even use the same dongle everytime?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to pre-register the dongles to the user in JAMF?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 19:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488074#M520631</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-24T19:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488075#M520633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We ran into a similar issue today, but I don't think it's an ISE issue as ISE just asks JAMF if this MAC is compliant and get a compliant, non-compliant, or unknown device response. It seems to be JAMF and having multiple MAC's for a device. The one I saw was a mac, dongle, and dock, so 3 MACs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 19:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488075#M520633</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-10-24T19:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488076#M520635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our desks are not permanent desks assigned to users so users float between desks all the time.&amp;nbsp; The desks themselves have either dongles, or docks.&amp;nbsp; So, multiple users could use the same dongle or doc throughout the week.&amp;nbsp; It would be nice if the JAMF query was always done with the WiFi MAC as that is the only consistent MAC address on most Macbooks now since they lack wired ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 20:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488076#M520635</guid>
      <dc:creator>Network Engineering</dc:creator>
      <dc:date>2017-10-24T20:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488077#M520636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could see that if you are running some kind of agent, but if not, you can only get the MAC on the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally, I want them to start using domain certs so I can not care about JAMF. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 20:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488077#M520636</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-10-24T20:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488078#M520637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow that's a lot of mac addresses for a single JAMF MDM profile to manage. And then you have multiple machines showing the same mac address depending on where the user moves from one to another desk. .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree we have no visibility of wireless mac when connecting via wired, there would need to be an agent that translated the MAC address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A couple other options:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Deploy ISE posture Anyconnect System Scan to manage wired compliance. &lt;/LI&gt;&lt;LI&gt;Don't run wired.&lt;/LI&gt;&lt;LI&gt;Require users to have their own dongle so that its unique and stays with them&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I asked our SME &lt;A href="https://community.cisco.com//u1/80461"&gt;imbashir&lt;/A&gt; to also see if he had any ideas.&lt;/P&gt;&lt;P&gt;There would need to be an enhancement to address without the need for MAC address, please reach out to JAMF and ISE Product Managers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 20:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488078#M520637</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-24T20:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488079#M520638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our workforce is extremely mobile.&amp;nbsp; Most users travel internationally between offices on a weekly or monthly basis.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deploy ISE posture Anyconnect System Scan to manage wired compliance.&lt;/P&gt;&lt;P&gt;This doesn't address the issue of checking for MDM registration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't run wired.&lt;/P&gt;&lt;P&gt;This is a requirement from the business.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Require users to have their own dongle so that its unique and stays with them&lt;/P&gt;&lt;P&gt;This unfortunately is not how the business is architected and Apple has moved wired ports into the Apple Monitors.&amp;nbsp; Most large enterprise Apple Macbook environments are using apple monitors that double as docks with ethernet ports.&amp;nbsp; As users move around their going to be using different Apple monitors and thus different ethernet ports.&amp;nbsp; When desks don't have Apple monitors, they would then use whatever dongle is available.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation would be to have the compliance module when installed, share the UDID with the MDM Registration checking process since ISE, JAMF, and the compliance module know the UDID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've spoken with &lt;A href="https://community.cisco.com//u1/80461"&gt;imbashir&lt;/A&gt; &lt;A href="https://community.cisco.com//u1/21224"&gt;psd&lt;/A&gt; and &lt;A href="https://community.cisco.com//u1/77207"&gt;mschmitz&lt;/A&gt; before on addressing some high priority bugs in the past and they have been pretty quick in addressing issues in the past.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 22:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488079#M520638</guid>
      <dc:creator>Network Engineering</dc:creator>
      <dc:date>2017-10-24T22:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: On-prem MDM with unknown MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488080#M520639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will be an enhancement to both ISE and the MDM provider , it’s not a bug like the other gentleman said&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have forwarded it along&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 22:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-prem-mdm-with-unknown-mac-address/m-p/3488080#M520639</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-24T22:44:08Z</dc:date>
    </item>
  </channel>
</rss>

