<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516711#M523275</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct they will be redirected and if compliant will get a COA and then be granted full access without redirect. This maybe still dependent on the vendor but this is the best scenario, best to lab it up with specific vendor and understand how it works as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wired redirection example can be grabbed from posture or guest examples here is one came up with a search&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html"&gt;Central Web Authentication with a Switch and Identity Services Engine Configuration Example - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Aug 2017 16:12:52 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-08-02T16:12:52Z</dc:date>
    <item>
      <title>Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516708#M523272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using ISE2.2P2 at customer site. They would like to check status for wired endpoints(Apple MAC) if it is registered with MDM to give final access. These endpoints are already enrolled for MDM off-prem, so is MDM redirection policy is required in ISE, for ISE to learn endpoint status first time ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried without MDM redirection authz policy and things are not working ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having hard time figuring out redirection policy if required .. redirect acl and actual redirection Authz profile and policy. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 20:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516708#M523272</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-08-01T20:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516709#M523273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mdm redirection is required to onboard the device as MDM Registered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01000.html#ID434&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also how to guides&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check under http://cs.co/ise-community look at mdm section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meraki I believe has a more seamless integration, there is a guide about that also&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 22:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516709#M523273</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T22:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516710#M523274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Referring to the same link. Highlighted text in image looks confusing. What will be the user experience in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These users who are already enrolled with MDM&amp;nbsp; outside ISE, still will be redirected but how will be they greeted on Splash page ? Will they directly get page saying that 'you have already enrolled with MDM....' . I am trying to work on this&lt;STRONG&gt; wired dot1X use case&lt;/STRONG&gt; but integration guide does not talk about wired redirection acl. Could you please provide some pointer what config need to be there on switch. We are NOT doing wireless authentication through ISE.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="109880" alt="mdm flow.png" class="image-1 jive-image" height="273" src="/legacyfs/online/fusion/109880_mdm flow.png" style="height: 273px; width: 734.726px;" width="735" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 23:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516710#M523274</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-08-01T23:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516711#M523275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct they will be redirected and if compliant will get a COA and then be granted full access without redirect. This maybe still dependent on the vendor but this is the best scenario, best to lab it up with specific vendor and understand how it works as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wired redirection example can be grabbed from posture or guest examples here is one came up with a search&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html"&gt;Central Web Authentication with a Switch and Identity Services Engine Configuration Example - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516711#M523275</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-02T16:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516712#M523276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we redirect with many MDM/EMM what are you trying with as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516712#M523276</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-02T16:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516713#M523277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really thanks for the reply... We are trying to use &lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;JAMF version 9.96.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;I got you, i will take reference of the link. So looks like I need to configure redirection acl in switch as well as downloadable Acl in ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;So in short , Need to permit&amp;nbsp; &lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;JAMF IP in dacl and &lt;/SPAN&gt; need to deny JAMF IP in redirection acl right ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Calibri',sans-serif; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:24:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516713#M523277</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-08-02T16:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516714#M523278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same as wireless just the opposite ☺&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516714#M523278</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-02T16:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516715#M523280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, It's not feasible. We are using JAMF Pro (Casper) as MDM, what we observed that JAMF does not capture wired MAC address in its db.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also apple MAC machines now does not have Ethernet port, so they need to attach to thunderbolt adapter which has its own MAC address. So even with different MDM provider if wired MAC address get captured, it will not be true identity of machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to document this observation somewhere, so people will be aware if they have similar requirement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 04:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3516715#M523280</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-08-18T04:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is MDM redirection necessary for ISE2.2P2 for endpoints already enrolled with MDM offpremises.</title>
      <link>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3825497#M523282</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been following this for a PoC of ISE &amp;amp; Jamf integration;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01000.html#ID259" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01000.html#ID259&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It says configure ACL on the WLC for the redirect. Is this the same ACL that the guest policy uses to redirect to ISE or is it a different ACL? If so what should this ACL look like?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 11:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-mdm-redirection-necessary-for-ise2-2p2-for-endpoints-already/m-p/3825497#M523282</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-25T11:39:14Z</dc:date>
    </item>
  </channel>
</rss>

