<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 3.1 Non-domain Joined Machines in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672574#M576781</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have created a policy for the wired devices. The devices which are connecting to network should act as a non compliant if Posture fails. (this policy is working fine). &lt;/P&gt;
&lt;P&gt;The only issue is I don't know how to segregate the domain-joined PCs and non-domain joined PCs in the policy. However the domain joined machines are using root certificates which are already added to ISE.&lt;/P&gt;
&lt;P&gt;I just want that a PC which is not domain joined how to make a policy for all the devices.&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2022 16:19:52 GMT</pubDate>
    <dc:creator>osman869</dc:creator>
    <dc:date>2022-08-19T16:19:52Z</dc:date>
    <item>
      <title>Cisco ISE 3.1 Non-domain Joined Machines</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672574#M576781</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have created a policy for the wired devices. The devices which are connecting to network should act as a non compliant if Posture fails. (this policy is working fine). &lt;/P&gt;
&lt;P&gt;The only issue is I don't know how to segregate the domain-joined PCs and non-domain joined PCs in the policy. However the domain joined machines are using root certificates which are already added to ISE.&lt;/P&gt;
&lt;P&gt;I just want that a PC which is not domain joined how to make a policy for all the devices.&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 16:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672574#M576781</guid>
      <dc:creator>osman869</dc:creator>
      <dc:date>2022-08-19T16:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.1 Non-domain Joined Machines</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672587#M576783</link>
      <description>&lt;P&gt;How would you want your non-domain joined PC to authorize? Do you want it to look to a different identity store? MAB? We will need additional information.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 17:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672587#M576783</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2022-08-19T17:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.1 Non-domain Joined Machines</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672597#M576784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Its kind of alien device and we dont have any information about them. On which attributes we can differentiate from domain-joined machines.&lt;/P&gt;
&lt;P&gt;So that when an alien devices comes it should go the Guest VLAN without configuring BYOD.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 17:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672597#M576784</guid>
      <dc:creator>osman869</dc:creator>
      <dc:date>2022-08-19T17:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.1 Non-domain Joined Machines</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672605#M576785</link>
      <description>&lt;P&gt;You can identify your domain computers by using the Certificate authentication conditions, for example "Issuer - Common Name."&lt;/P&gt;&lt;P&gt;If you are looking for computers to gain access without certificates installed, MAB may be your only option. Ensure your profiling policies are in place to properly identify that they are indeed workstations. Within your MAB policy you would then have to set your authorization result to assign the Guest VLAN to anything that falls into that profiling group. I would make sure the Guest VLAN is restricted as much as possible as anyone can now plug in a workstation and be authorized. It should be just enough access for you to access and install certificates.&lt;/P&gt;&lt;P&gt;This is just my way of thinking, I would like to see what other suggestions there are.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 18:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672605#M576785</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2022-08-19T18:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.1 Non-domain Joined Machines</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672823#M576790</link>
      <description>&lt;P&gt;How do you &lt;EM&gt;identify&lt;/EM&gt; your non-domain joined assets? I suspect if they are unjoined then they are not managed and so you fall back to using MAC addresses with MAB. Do you have them in a list such as an ISE endpoint group that you put them into? Or do you treat them all as unknown/untrusted Guests?&amp;nbsp; I suspect you default to Guest. So give them Guest access.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 15:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-1-non-domain-joined-machines/m-p/4672823#M576790</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-08-20T15:48:03Z</dc:date>
    </item>
  </channel>
</rss>

