<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Manage MAC Address Randomization in Dual SSID BYOD ISE 3.3? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-manage-mac-address-randomization-in-dual-ssid-byod-ise-3/m-p/5073559#M588852</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Context:&lt;/STRONG&gt; I am currently testing a BYOD setup involving dual SSIDs using Cisco ISE 3.3 for mobile devices. The configuration process begins with an open SSID, followed by a secure SSID connection via TLS once the profile and certificate are retrieved from ISE.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Certificate Configuration:&lt;/STRONG&gt; The certificate template includes both the GUID and MAC address, ensuring that the certificate issued by ISE contains these fields.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue Encountered:&lt;/STRONG&gt; The challenge arises with MAC address randomization. For instance, an iPhone may connect to the open SSID using one MAC address and then switch to a different MAC address when connecting to the secure SSID.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Specific Problem:&lt;/STRONG&gt; This becomes problematic when attempting to manage device statuses such as marking a device as stolen or lost in my device management portal. The portal only recognizes the MAC address used for the initial open SSID connection, which complicates the security measures for the subsequent secure SSID connection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; How can I address this issue of MAC address discrepancy in dual SSID configurations, particularly when dealing with security protocols and device management? Is there a way to configure the device or ISE settings to recognize or adapt to MAC address randomization?&lt;/P&gt;
&lt;P&gt;I appreciate any insights or suggestions from the community. Thank you!&lt;BR /&gt;&lt;STRONG&gt;NOTE: I am not using AD here; instead, I am using LDAP.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2024 08:25:19 GMT</pubDate>
    <dc:creator>ISENAC1122</dc:creator>
    <dc:date>2024-04-19T08:25:19Z</dc:date>
    <item>
      <title>How to Manage MAC Address Randomization in Dual SSID BYOD ISE 3.3?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-manage-mac-address-randomization-in-dual-ssid-byod-ise-3/m-p/5073559#M588852</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Context:&lt;/STRONG&gt; I am currently testing a BYOD setup involving dual SSIDs using Cisco ISE 3.3 for mobile devices. The configuration process begins with an open SSID, followed by a secure SSID connection via TLS once the profile and certificate are retrieved from ISE.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Certificate Configuration:&lt;/STRONG&gt; The certificate template includes both the GUID and MAC address, ensuring that the certificate issued by ISE contains these fields.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue Encountered:&lt;/STRONG&gt; The challenge arises with MAC address randomization. For instance, an iPhone may connect to the open SSID using one MAC address and then switch to a different MAC address when connecting to the secure SSID.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Specific Problem:&lt;/STRONG&gt; This becomes problematic when attempting to manage device statuses such as marking a device as stolen or lost in my device management portal. The portal only recognizes the MAC address used for the initial open SSID connection, which complicates the security measures for the subsequent secure SSID connection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; How can I address this issue of MAC address discrepancy in dual SSID configurations, particularly when dealing with security protocols and device management? Is there a way to configure the device or ISE settings to recognize or adapt to MAC address randomization?&lt;/P&gt;
&lt;P&gt;I appreciate any insights or suggestions from the community. Thank you!&lt;BR /&gt;&lt;STRONG&gt;NOTE: I am not using AD here; instead, I am using LDAP.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 08:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-manage-mac-address-randomization-in-dual-ssid-byod-ise-3/m-p/5073559#M588852</guid>
      <dc:creator>ISENAC1122</dc:creator>
      <dc:date>2024-04-19T08:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to Manage MAC Address Randomization in Dual SSID BYOD ISE 3.3?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-manage-mac-address-randomization-in-dual-ssid-byod-ise-3/m-p/5073581#M588853</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/randomized-changing-mac-dg.html" target="_self"&gt;Randomized and Changing MAC Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/random-mac-address-how-to-deal-with-it-using-ise/ta-p/4049321" target="_blank"&gt;Random MAC Address - How to deal with it using ISE&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 08:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-manage-mac-address-randomization-in-dual-ssid-byod-ise-3/m-p/5073581#M588853</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-04-19T08:49:18Z</dc:date>
    </item>
  </channel>
</rss>

