<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE MAB for Cisco IP phone without profiling license. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695950#M577472</link>
    <description>&lt;P&gt;Yes, voice domain permission would be required. It does seem that the traffic coming from the phones is not matching the right authorization profile. Would you mind sharing sanitized screenshots of your authentication and authorization rules for review?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 13:08:35 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2022-09-29T13:08:35Z</dc:date>
    <item>
      <title>ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695872#M577466</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I am trying to setup our ISE for Cisco IP phone and we do not have license to support profiling. do you have a step by step guide or something so I can copy it? I have tried everything so far that I know but it wouldnt work as I am keep getting the following error:&lt;/P&gt;&lt;P&gt;resolution:&amp;nbsp;Authorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results.&lt;/P&gt;&lt;P&gt;root cause:&amp;nbsp;Selected Authorization Profile contains ACCESS_REJECT attribute&lt;/P&gt;&lt;P&gt;ISE Version is: 3.2&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 10:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695872#M577466</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T10:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695912#M577469</link>
      <description>&lt;P&gt;I think you can create an identity group, importing/moving the phones' MAC addresses into the identity group, and then reference the identity group on the authorization rule. That should match the traffic coming from the phones without relying on profiling at all. The downside of this is that you need to add any additional phone MAC address to the identity group.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 12:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695912#M577469</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T12:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695924#M577471</link>
      <description>&lt;P&gt;Hi Aref.&lt;/P&gt;&lt;P&gt;I have done just that but getting the below error- also, I have only selected "voice domain" in the result profile - is that right?:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event :&amp;nbsp;5434 Endpoint conducted several failed authentications of the same scenario&lt;/P&gt;&lt;P&gt;Failure Reason:&amp;nbsp;15039 Rejected per authorization profile&lt;/P&gt;&lt;P&gt;Resolution:&amp;nbsp;Authorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results.&lt;/P&gt;&lt;P&gt;Root cause:&amp;nbsp;Selected Authorization Profile contains ACCESS_REJECT attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 12:50:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695924#M577471</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T12:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695950#M577472</link>
      <description>&lt;P&gt;Yes, voice domain permission would be required. It does seem that the traffic coming from the phones is not matching the right authorization profile. Would you mind sharing sanitized screenshots of your authentication and authorization rules for review?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 13:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4695950#M577472</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T13:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696080#M577476</link>
      <description>&lt;P&gt;thanks Aref, I can see the right authZ policy is selected in the logs but still access_reject is chosen:&amp;nbsp;&lt;/P&gt;&lt;P&gt;(check the attached screenshot)&lt;/P&gt;&lt;P&gt;there was a default IP Phone group so I added the MAC to this group statically.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696080#M577476</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T14:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696089#M577477</link>
      <description>&lt;P&gt;Mmm, could you please check in the authorization profile the access type? it is the first option when you open up the authorization profile, and it should be set to "ACCESS_ACCEPT", maybe it was set to "ACCESS_REJECT" accidentally?!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696089#M577477</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T14:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696096#M577478</link>
      <description>&lt;P&gt;The "&lt;STRONG&gt;Event : 5434 Endpoint conducted several failed authentications of the same scenario&lt;/STRONG&gt;" message suggests the client is being blacklisted by ISE - see thread below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-and-failed-authentications-conducted-by-endpoints/td-p/2971530" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-and-failed-authentications-conducted-by-endpoints/td-p/2971530&lt;/A&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696096#M577478</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-09-29T14:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696100#M577480</link>
      <description>&lt;P&gt;its definitely set to Access_Accept - checked it many times over.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696100#M577480</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T14:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696115#M577482</link>
      <description>&lt;P&gt;Could you please try to create an new authorization profile from the scratch, not by cloning the existing one, and apply it to the authorization rule and see if that makes any difference?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696115#M577482</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T14:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696127#M577483</link>
      <description>tried that over a few times as well.&lt;BR /&gt;&lt;BR /&gt;The only thing selected in authorization result profile is voice domain&lt;BR /&gt;though and access-accept</description>
      <pubDate>Thu, 29 Sep 2022 15:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696127#M577483</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T15:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696135#M577485</link>
      <description>&lt;P&gt;Can you please share the complete failure log page as a screenshot for review?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696135#M577485</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T15:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696140#M577486</link>
      <description>&lt;P&gt;sure, please see atatched:&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696140#M577486</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T15:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696152#M577487</link>
      <description>&lt;P&gt;thanks Andrew, there's no anomalous client supression settings in "&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Radius, Suppress Anomalous Clients"&lt;/STRONG&gt; as the thread suggests. we are running version 3 patch 2.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696152#M577487</guid>
      <dc:creator>ali007</dc:creator>
      <dc:date>2022-09-29T15:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE MAB for Cisco IP phone without profiling license.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696161#M577488</link>
      <description>&lt;P&gt;Thanks. It seems ISE is complaining about the network device profile. What network device profile have you selected in the phones authorization profile? that option should be the second from top. Could you please try to set that to "any" and see if this makes any difference?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 16:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-for-cisco-ip-phone-without-profiling-license/m-p/4696161#M577488</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-29T16:02:14Z</dc:date>
    </item>
  </channel>
</rss>

