<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.1 Linux BYOD Client provisioning in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549361#M520969</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: 14.666666984558105px;"&gt;Would recommend working through TAC to debug, please update with the solution&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Oct 2017 14:39:37 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-10-17T14:39:37Z</dc:date>
    <item>
      <title>ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549350#M520955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please assist where to I get the client provisioning for Linux machines? I am unable to download direct from ISE. Or please assist on the configuration of this. I get device not supported on the BYOD flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 10:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549350#M520955</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T10:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549351#M520957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no posture compliance (anyconnect system scan) or BYOD flow support for linux devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For EAP-TLS cert auth to ISE&lt;/P&gt;&lt;P&gt;In ISE you can use our certificate provisioning portal to generate endpoint certificate for linux and can manually install it. There is API that can help automate as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 11:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549351#M520957</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-09T11:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549352#M520958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the solution is for wired so I need a way to profile the device as linux and then get the user to login via CWA bypass client provision to match AD group and provide rights as per AD group. Any way in doing this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 11:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549352#M520958</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T11:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549353#M520960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Certainly you can profile and send them to a CWA portal. However there is a chicken egg thing going on here.. If it’s a new device, unless you specify a list of mac addresses of your linux machines then we need to hit a portal to find out if it is a linux machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain further what you would like to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step by step what is supposed to happen with the following when they first connect&lt;/P&gt;&lt;P&gt;linux devices&lt;/P&gt;&lt;P&gt;windows/apple mac&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 11:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549353#M520960</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-09T11:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549354#M520962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question here is if I enable under the &lt;SPAN class="nested xwtBreadcrumb"&gt;&lt;A&gt;Profiler Policy List&lt;/A&gt;&lt;SPAN class="xwtBreadcrumbSeparator"&gt; &amp;gt; workstation (dell, hp and so on) NMAP what kind CPU will this add if this is enabled? Running ISE 2.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 11:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549354#M520962</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T11:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549355#M520963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This wouldn’t work because you’re trying to profile as linux workstation. What good would it do you to identify the type of Physical workstation they are using? Does a specific type of physical workstation (example HP) only run linux?? Are you running linux on multiple different type of hardware?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If these are company owned linux then you might need to somehow identify&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you learn about profiling here - https://communities.cisco.com/docs/DOC-68156&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please explain the flows you are wanting to support from the wired switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549355#M520963</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-09T12:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549356#M520964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Catch all rule CWA need to be able to login with Linux machine no client provision enabled for Linux only possible or not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549356#M520964</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T12:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549357#M520965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found this will try the below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-wired-captive-portal/td-p/2563656" title="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-wired-captive-portal/td-p/2563656"&gt;ISE Wired captive portal - Cisco Support Community&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549357#M520965</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T12:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549358#M520966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found this will try the below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-wired-captive-portal/td-p/2563656" title="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-wired-captive-portal/td-p/2563656"&gt;ISE Wired captive portal - Cisco Support Community&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549358#M520966</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T12:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549359#M520967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is this setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-10-09 at 2.30.57 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/111859_Screen Shot 2017-10-09 at 2.30.57 PM.png" style="height: 133px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;There is no way to call this out in client provisioning policy.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;IMG alt="Screen Shot 2017-10-09 at 2.23.46 PM.png" class="jive-image image-2" src="/legacyfs/online/fusion/111860_Screen Shot 2017-10-09 at 2.23.46 PM.png" style="height: 387px; width: 620px;" /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Its still not clear on your flows.. How do you want to handle other OS. Are you doing BYOD certificate provisioning or posture.. etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to call the TAC and explain this to have a detailed conversation. Or request through your sales channel to discuss with an ISE expert. From this thread you are not providing enough context on what you're wanting to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could possibly do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if wired_mab and windows/mac and using certificate then permitWindowsMACaccess&lt;/P&gt;&lt;P&gt;if wired_mab and linux then PermitLinuxAccess&lt;/P&gt;&lt;P&gt;if wired_mab and windows/mac then BYOD&lt;/P&gt;&lt;P&gt;if wired_mab then redirect to CWA (when they hit the portal they will be profiled)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549359#M520967</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-09T12:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549360#M520968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below. Network setup assistant pushed below settings with Public ROOT CA from ISE. No EAP-TLS is used in this deployment.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="268" src="https://community.cisco.com/afbecd6f-7e3f-41e5-a84a-6fab4f8c7341" style="max-width: 1200px; max-height: 900px; height: 267.7654320987654px; width: 529px;" width="529" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2" height="325" src="https://community.cisco.com/legacyfs/online/fusion/111861_pastedImage_2.png" style="width: 620px; height: 426px;" width="473" /&gt;&lt;/P&gt;&lt;P&gt;You have let say 10000 clients which some of them are domain user but private machines.&lt;/P&gt;&lt;P&gt;Only domain machines are postured checked with any connect clients and posture agent. Working on all windows machines. EAP Chain result machine and user authenticated. &lt;/P&gt;&lt;P&gt;Rest of machines are BYOD machines. Above native supplicant profile is used and send to Windows and MAC OX users. Tested working. User can be identified as staff or non staff and authorization profiles with rights enforced. &lt;/P&gt;&lt;P&gt;Now you have users how have their own machines with Linux. For them to access corparate resource you need to identify them. You send them to a portal to login (catch all mab CWA rule ) to capture their details, from here device not supported displayed on the BYOD for linux machines. The question here is how do you allow these machines on the network without any user interaction or little and how do you identify the user for this machine.&lt;/P&gt;&lt;P&gt;Settings already enabled as per your screen shot.&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" height="206" src="https://community.cisco.com/a583646d-5ebc-4614-ae46-fc6d20ad3f77" style="max-width: 1200px; max-height: 900px; height: 206px; width: 635.4755784061697px;" width="635" /&gt;&lt;/P&gt;&lt;P&gt;Hope this information helps or if still unclear I can add more if you need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549360#M520968</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-09T15:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549361#M520969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: 14.666666984558105px;"&gt;Would recommend working through TAC to debug, please update with the solution&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549361#M520969</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-17T14:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549362#M520970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am currently doing is the following. MAB rule with CWA then user login with AD credential to get the machine profiled as linux. I have set the Native supplicant provisioning policy Unavailable " Allow Network Access" under the Administration settings to get passed the client provision issue for Linux device not support is that is now displayed but network access is allowed. With the COA user now falls in the Wired_BYOD_Devices and combined with Authorization rules to match Linux and Wired_BYOD_Devices user is then redirected to Guest Portal with no BYOD flow. When user then authenticated against AD correct access is allocated with a DACL. This only happens once with the redirect to 2 different Portals. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAB with CWA Guest Portal flow with BYOD&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="77" src="https://community.cisco.com/8f3b57ea-f8ee-4daa-9ac8-235cc6494023" style="max-width: 1200px; max-height: 900px; width: 537px; height: 77.4175px;" width="537" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2" height="116" src="https://community.cisco.com/554a3489-bcc9-48cb-92aa-e5661b5adcb4" style="max-width: 1200px; max-height: 900px; width: 536px; height: 115.68666666666667px;" width="536" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" height="45" src="https://community.cisco.com/2adb62f0-93b4-4d25-b8e4-6096d9ed7f45" style="max-width: 1200px; max-height: 900px; width: 583px; height: 45.1825px;" width="583" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other issue I am now faces with is below when a guest logs in.&lt;/P&gt;&lt;H2 class="message-subject"&gt;&lt;SPAN class="lia-message-unread"&gt;&lt;/SPAN&gt;&lt;/H2&gt;&lt;H5&gt;[ 400 ] Bad Request,The request is invalid due to malformed syntax or invalid data&lt;/H5&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2017 10:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549362#M520970</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-10-18T10:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Linux BYOD Client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549363#M520971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please work through the tac sorry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2017 14:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-linux-byod-client-provisioning/m-p/3549363#M520971</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-18T14:28:16Z</dc:date>
    </item>
  </channel>
</rss>

