<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE+WLC Partial MAC Address Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4435509#M568541</link>
    <description>&lt;P&gt;Couple of suggestions :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. the document have clear steps : (spend some time read, and ask what steps it was not clearn) - the document also provide with screenshot - just like spoon feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.network-node.com/blog/2016/1/2/ise-20-profiling" target="_blank" rel="nofollow noopener noreferrer"&gt;http://www.network-node.com/blog/2016/1/2/ise-20-profiling&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you not in a postion to hire consultant, then you need to spend time reading the documents understand and deploy and test it.&lt;/P&gt;
&lt;P&gt;it required some understand, its not onself you can do 123 kinda.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;time is value for every one, so we do best to support community (we do encourage people to learn and improve, at the same time we also learn here where possible).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 16:58:00 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-07-19T16:58:00Z</dc:date>
    <item>
      <title>ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433365#M568465</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a small network with a few WLC's each with multiple WLANs, as well as an ISE server. One of the SSID's I have is open, and I would like to authenticate it using ISE. All of the clients connecting to this network will have one of three different OUIs, (first 6 digits of the MAC), so I would like to set up authentication using that. Only clients with those three OUI's will be allowed, and all others will be blocked. I am fairly new to ISE and not sure where to start on this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 21:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433365#M568465</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-14T21:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433393#M568467</link>
      <description>&lt;P&gt;Don't you think is the security risk only "&lt;SPAN&gt;(first 6 digits of the MAC)"&amp;nbsp; - why not have the full MAC address of the device and make Profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any reason you can not do that,&amp;nbsp; MAB only used if the supplicant can not be installed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 22:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433393#M568467</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-14T22:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433404#M568468</link>
      <description>&lt;P&gt;I considered that option. The problem with that is I have over 200,000 unique devices and that list is continuously growing, so I would have a massive list of devices that would continuously have to be updated. I realize this is not optimal from a security perspective, but individual mac filtering is not feasible.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 22:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433404#M568468</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-14T22:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433581#M568477</link>
      <description>&lt;P&gt;Do you have any other layered authentication (like how we do BYOD).&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 07:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433581#M568477</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-15T07:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433927#M568490</link>
      <description>&lt;P&gt;No, I am just trying to authenticate by OUI.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 16:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4433927#M568490</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-15T16:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434058#M568494</link>
      <description>&lt;P&gt;It's your Governance and security policy of the business&amp;nbsp; - technically works, but as I head up with security risk.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 21:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434058#M568494</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-15T21:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434101#M568498</link>
      <description>&lt;P&gt;Huge security with open SSID and only filtering on OUI, even if it's an isolated network. Maybe add some profiling? or switch to a PSK + OUI filtering?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 22:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434101#M568498</guid>
      <dc:creator>littleyoda</dc:creator>
      <dc:date>2021-07-15T22:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434507#M568511</link>
      <description>&lt;P&gt;Thank you for the reply, however, at this moment I am not worried about security. I am simply trying to figure out how to implement partial mac auth in the first place. If you know how any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 16:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434507#M568511</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-16T16:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434508#M568512</link>
      <description>&lt;P&gt;I appreciate the replies. Ignoring security risks for the moment, if you know how to implement partial mac authorization using ISE any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 16:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434508#M568512</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-16T16:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434537#M568513</link>
      <description>&lt;P&gt;If the business not worried much, you can carry and it works as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.network-node.com/blog/2016/1/2/ise-20-profiling" target="_blank"&gt;http://www.network-node.com/blog/2016/1/2/ise-20-profiling&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 17:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434537#M568513</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-16T17:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434539#M568514</link>
      <description>&lt;P&gt;My point is I do not know how to implement this, as in, I do not know how to configure ISE to do this.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 17:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434539#M568514</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-16T17:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434765#M568520</link>
      <description>&lt;P&gt;the steps are clear in the document, if you are worried much, I would suggest hiring a consultant for the piece of work as a mini project&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jul 2021 09:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4434765#M568520</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-17T09:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4435477#M568539</link>
      <description>&lt;P&gt;The steps may be clear to you, but they are not to me. That is why I am asking for help here. Which document are you referring to? Also, I do not have money to hire a consultant, which again is why I am asking for help here.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 16:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4435477#M568539</guid>
      <dc:creator>r3kr4p</dc:creator>
      <dc:date>2021-07-19T16:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE+WLC Partial MAC Address Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4435509#M568541</link>
      <description>&lt;P&gt;Couple of suggestions :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. the document have clear steps : (spend some time read, and ask what steps it was not clearn) - the document also provide with screenshot - just like spoon feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.network-node.com/blog/2016/1/2/ise-20-profiling" target="_blank" rel="nofollow noopener noreferrer"&gt;http://www.network-node.com/blog/2016/1/2/ise-20-profiling&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you not in a postion to hire consultant, then you need to spend time reading the documents understand and deploy and test it.&lt;/P&gt;
&lt;P&gt;it required some understand, its not onself you can do 123 kinda.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;time is value for every one, so we do best to support community (we do encourage people to learn and improve, at the same time we also learn here where possible).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 16:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-partial-mac-address-authentication/m-p/4435509#M568541</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-19T16:58:00Z</dc:date>
    </item>
  </channel>
</rss>

