<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - unable to onboard Lenovo laptops in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165885#M591391</link>
    <description>&lt;P&gt;What is the use-case to allow unmanaged/unknown endpoints onto the protected network?&amp;nbsp; Why not add these machines to the domain?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2024 11:23:30 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-08-26T11:23:30Z</dc:date>
    <item>
      <title>ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164932#M591349</link>
      <description>&lt;P&gt;Hello everyone, I would like to ask for your help with a strange issue.&lt;/P&gt;&lt;P&gt;We currently have several BYOD devices that are not in the domain and we need to onboard them. These are all Lenovo laptops. They will connect to the network via username and password and successfully download the Network Setup Assistant via the BYOD portal as expected. When I run Network Setup Assistant, I see that the profile is being downloaded but in a few seconds it stops and says . "Failed to discover ISE. Reconnect to the network and try again".&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scr2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/226943i8386E883443F214B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scr2.png" alt="scr2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I don't know how to troubleshoot this at all. When I do the same thing on a Dell laptop, it means I start the Network Setup Assistant, the process goes successfully to the end. We updated Windows OS, drivers, and also checked certificates but we cannot figure out where the problem is.&amp;nbsp;&lt;SPAN&gt;The latest Windows 11 is installed. But this happens only with Lenovo with Windows 11. Dell with Windows 11 and Lenovo with Windows 10 work perfectly.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The content of spwProgileLog is here:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Fri Aug 23 12:51:48 2024] Logging started&lt;BR /&gt;[Fri Aug 23 12:51:48 2024] SPW Version: 3.0.0.3&lt;BR /&gt;[Fri Aug 23 12:51:48 2024] System locale is [en]&lt;BR /&gt;[Fri Aug 23 12:51:48 2024] Loading messages for english...&lt;BR /&gt;[Fri Aug 23 12:51:48 2024] Initializing profile&lt;BR /&gt;[Fri Aug 23 12:51:49 2024] Found 2 interfaces&lt;BR /&gt;[Fri Aug 23 12:51:49 2024] Found 0 interfaces&lt;BR /&gt;[Fri Aug 23 12:51:49 2024] SPW is running as High integrity Process - 12288&lt;BR /&gt;[Fri Aug 23 12:51:49 2024] GetProfilePath: searched path = C:\Users\Admin\AppData\Local\Temp\ for file name = spwProfile.xml result: 0&lt;BR /&gt;[Fri Aug 23 12:51:49 2024] GetProfilePath: searched path = C:\Users\Admin\AppData\Local\Temp\Low for file name = spwProfile.xml result: 0&lt;BR /&gt;[Fri Aug 23 12:51:51 2024] Profile xml not found Downloading profile configuration...&lt;BR /&gt;[Fri Aug 23 12:51:51 2024] Downloading profile configuration...&lt;BR /&gt;[Fri Aug 23 12:51:51 2024] Discovering ISE using default gateway&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] Identifying wired and wireless network interfaces, total active interfaces: 0&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] DiscoverISE - start&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] DiscoverISE input parameter : strUrl [&lt;A href="http://enroll.cisco.com/auth/discovery/" target="_blank" rel="noopener"&gt;http://enroll.cisco.com/auth/discovery/&lt;/A&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] [HTTPConnection] CrackUrl: host = enroll.cisco.com, path = /auth/discovery/, user = , port = 80, scheme = 3, flags = 0&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] [HTTPConnection] HttpSendRequest: header = Accept: */*&lt;BR /&gt;headerLength = 12 data = dataLength = 0&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] HTTP Response header: [HTTP/1.1 200 OK&lt;BR /&gt;Location: &lt;A href="https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/" target="_blank" rel="noopener"&gt;https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/&lt;/A&gt;&lt;BR /&gt;Content-Type: text/html&lt;BR /&gt;Content-Length: 476&lt;/P&gt;&lt;P&gt;] HTTP Content: [&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&amp;lt;TITLE&amp;gt; Web Authentication Redirect&amp;lt;/TITLE&amp;gt;&amp;lt;META http-equiv="Cache-control" content="no-cache"&amp;gt;&amp;lt;META http-equiv="Pragma" content="no-cache"&amp;gt;&amp;lt;META http-equiv="Expires" content="-1"&amp;gt;&amp;lt;META http-equiv="refresh" content="1; URL=&lt;A href="https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/" target="_blank" rel="noopener"&gt;https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/&lt;/A&gt;"&amp;gt;&amp;lt;/HEAD&amp;gt;&amp;lt;/HTML&amp;gt;&lt;BR /&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] getUrlFromResponse - Server response body lower case [&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt; web authentication redirect&amp;lt;/title&amp;gt;&amp;lt;meta http-equiv="cache-control" content="no-cache"&amp;gt;&amp;lt;meta http-equiv="pragma" content="no-cache"&amp;gt;&amp;lt;meta http-equiv="expires" content="-1"&amp;gt;&amp;lt;meta http-equiv="refresh" content="1; url=&lt;A href="https://ISEserver.ourdomain.local:8443/portal/gateway?sessionid=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/" target="_blank" rel="noopener"&gt;https://ISEserver.ourdomain.local:8443/portal/gateway?sessionid=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&amp;amp;redirect=enroll.cisco.com/auth/discovery/&lt;/A&gt;"&amp;gt;&amp;lt;/head&amp;gt;&amp;lt;/html&amp;gt;&lt;BR /&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] getUrlFromResponse - returning url extracted from meta tag [&lt;A href="https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad" target="_blank" rel="noopener"&gt;https://ISEserver.ourdomain.local:8443/portal/gateway?sessionId=c0a867450023f31666c86713&amp;amp;portal=ad69d838-621f-494d-ba60-47febae4dbdf&amp;amp;action=nsp&amp;amp;token=6b41892bc450f9cca02c510754db37ad&lt;/A&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] Discovered ISE - : [ISEserver.ourdomain.local, sessionId: c0a867450023f31666c86713]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] DiscoverISE - end&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] Discovered ISE using cisco url: [&lt;A href="http://enroll.cisco.com/auth/discovery/" target="_blank" rel="noopener"&gt;http://enroll.cisco.com/auth/discovery/&lt;/A&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] Successfully Discovered ISE: ISEserver.ourdomain.local, session id: c0a867450023f31666c86713, macAddress:&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] GetProfile - start&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] [HTTPConnection] CrackUrl: host = ISEserver.ourdomain.local, path = /auth/provisioning/evaluate?typeHint=SPWConfig&amp;amp;referrer=Windows&amp;amp;spw_version=3.0.0.3&amp;amp;session=c0a867450023f31666c86713&amp;amp;os=Windows All, user = , port = 8905, scheme = 4, flags = 8388608&lt;BR /&gt;[Fri Aug 23 12:51:52 2024] [HTTPConnection] HttpSendRequest: header = Accept: */*&lt;BR /&gt;headerLength = 12 data = dataLength = 0&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Warning - [HTTPConnection:RetrySendRequest] InternetOpen() failed with code: [12057], msg: [It was not possible to connect to the revocation server or a definitive response could not be obtained.&lt;BR /&gt;]&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] [HTTPConnection] All CRL Checks are off&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] [HTTPConnection] HttpSendRequest: header = Accept: */*&lt;BR /&gt;headerLength = 12 data = dataLength = 0&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Received redirect to location null&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] [HTTPConnection] CrackUrl: host = ISEserver.ourdomain.local, path = /auth/provisioning/download/e35e7769-8a5e-4c4a-a454-ac0262f9f0bb/NSA_BYOD_EXT.xml?sessionId=c0a867450023f31666c86713&amp;amp;os=WINDOWS_10_ALL, user = , port = 8443, scheme = 4, flags = 8388608&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] [HTTPConnection] HttpSendRequest: header = Accept: */*&lt;BR /&gt;headerLength = 12 data = dataLength = 0&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] GetProfile - end&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Successfully retrieved profile xml&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] using V2 xml version&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] parsing wireless connection setting&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Certificate template: [keytype:RSA, keysize:2048, subject:OU=XXX;O=XXX;L=XXX;ST=XXX;C=XXX, SAN:MAC]&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] set ChallengePwd&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Starting parsing proxy configuration&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] ProxySettings key was not found in the configuration xml&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] found redirect URL: &lt;A href="https://www.domain.com" target="_blank" rel="noopener"&gt;https://www.domain.com&lt;/A&gt;&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] Identifying wired and wireless network interfaces, total active interfaces: 0&lt;BR /&gt;[Fri Aug 23 12:51:53 2024] WirelessProfile::StartWLanSvc - Start&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Wlansvc service is in Auto mode ...&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Wlansvc is running in auto mode...&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] WirelessProfile::StartWLanSvc - End&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Found [1] wireless interfaces ...&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Wireless interface 1 - Desc: [Qualcomm FastConnect 6900 Wi-Fi 6E Dual Band Simultaneous (DBS) WiFiCx Network Adapter], Guid: [{FBE6ACB5-7B7D-4709-BFD1-7850CE089CA9}]...&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Wireless interface - Mac address: 8C-3B-4A-4E-EC-6A&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Identifying wired and wireless interfaces...&lt;BR /&gt;[Fri Aug 23 12:51:54 2024] Wireless interface [{FBE6ACB5-7B7D-4709-BFD1-7850CE089CA9}] will be configured...&lt;/P&gt;&lt;P&gt;Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 11:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164932#M591349</guid>
      <dc:creator>B A</dc:creator>
      <dc:date>2024-08-23T11:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164949#M591351</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Is there perhaps any (other) firewalling local active or for instance more enhanced win11 firewalling settings on the Lenovo's w.r.t other devices ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 11:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164949#M591351</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-08-23T11:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164993#M591352</link>
      <description>&lt;P&gt;Thanks for the suggestion but I don't see anything. Windows Firewall and antivirus are turned off but it makes no difference.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 12:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5164993#M591352</guid>
      <dc:creator>B A</dc:creator>
      <dc:date>2024-08-23T12:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165022#M591353</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Just asking : anything special like lenovo proprietary firewalling for windows 11 ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165022#M591353</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-08-23T13:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165034#M591355</link>
      <description>&lt;P&gt;I am not aware of it.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165034#M591355</guid>
      <dc:creator>B A</dc:creator>
      <dc:date>2024-08-23T13:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165055#M591356</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Is the Cisco-ISE &lt;STRONG&gt;versio&lt;/STRONG&gt;n sufficiently recent , I would take &lt;STRONG&gt;&amp;gt;3.0&lt;/STRONG&gt; as a requirement.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; + Check if this stuff is interesting&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-and-lenovo-thunderbolt-docks-ise-will-put-the-laptop-user/m-p/4051345#M559100" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-and-lenovo-thunderbolt-docks-ise-will-put-the-laptop-user/m-p/4051345#M559100&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 14:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165055#M591356</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-08-23T14:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165769#M591382</link>
      <description>&lt;P&gt;ISE version is&amp;nbsp;&lt;SPAN&gt;3.1.0.518.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also checked the link but it doesn't seem relevant to our issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 05:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165769#M591382</guid>
      <dc:creator>B A</dc:creator>
      <dc:date>2024-08-26T05:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165772#M591383</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- You may want to contact Cisco's &lt;U&gt;&lt;STRONG&gt;TAC ,&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 05:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165772#M591383</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-08-26T05:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - unable to onboard Lenovo laptops</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165885#M591391</link>
      <description>&lt;P&gt;What is the use-case to allow unmanaged/unknown endpoints onto the protected network?&amp;nbsp; Why not add these machines to the domain?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 11:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-unable-to-onboard-lenovo-laptops/m-p/5165885#M591391</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-08-26T11:23:30Z</dc:date>
    </item>
  </channel>
</rss>

