<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3 - licensing and one device wired and wireless at same time in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204959#M592276</link>
    <description>&lt;P&gt;and is it possible to force the feature license for some endpoint manually?? and can some client use only Premier and some only Essential? exact example: client authorize using 802.1x (which uses essentials) and then Posture scan will occur (which uses Premier) - which license will be counted?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2024 05:52:42 GMT</pubDate>
    <dc:creator>Tibor M</dc:creator>
    <dc:date>2024-10-08T05:52:42Z</dc:date>
    <item>
      <title>ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204863#M592273</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;trying to figure out how ISE will count licensing when 1 laptop is connected at same time through wired 802.1X either wireless.&lt;/P&gt;
&lt;P&gt;The situation is, that we are pushing WiFi profile to all Windows machines through GPO and setting there "automatically connect", so each laptop is connecting now automatically using certificates and 802.1X on ISE. But each laptop can be at same time connected to docking station, which provides wired connectivity.&lt;/P&gt;
&lt;P&gt;Is there any way how to tell ISE - hey, this laptop has 2 MACs, one user, count it as one endpoint?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 23:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204863#M592273</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2024-10-07T23:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204885#M592275</link>
      <description>&lt;P&gt;Nope - two unique MAC addresses will count as two different ISE endpoints - depending on how you authorized each of those MAC addresses, will count towards an Essentials, Advantage or Premier license. No way around it.&amp;nbsp; Perhaps you can write some kind of a script on the laptop to shut the Wi-Fi down while the Ethernet adapter has a valid connection, and vice-versa.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 02:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204885#M592275</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-08T02:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204959#M592276</link>
      <description>&lt;P&gt;and is it possible to force the feature license for some endpoint manually?? and can some client use only Premier and some only Essential? exact example: client authorize using 802.1x (which uses essentials) and then Posture scan will occur (which uses Premier) - which license will be counted?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 05:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204959#M592276</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2024-10-08T05:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204983#M592278</link>
      <description>&lt;P&gt;ISE will only count one license per endpoint - as per the DNA model, all the higher tiers contain the license ability of the lower tiers. That means, a profiled endpoint will need Advantage, a Posture scanned AuthZ will need Premier, and a regular 802.1X/MAB needs Essentials. Basically, whatever the ISE Policy Set AuthZ ended up using in its rules. And I believe it will use the most expensive license if there is a complex AuthZ rule that contains mixture of Essentials/Advantage/Premier logic.&lt;/P&gt;
&lt;P&gt;Have a &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/ise-licensing-guide-og.html" target="_self"&gt;look here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 06:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5204983#M592278</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-08T06:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5206293#M592350</link>
      <description>&lt;P&gt;this is sad. I understand it from income point of view for Cisco, but in real life, why should same device, just connected in parallel to wire and wireless use 2 licenses if it's authorized with same certificate and same user, just because of 2 MACs.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 07:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5206293#M592350</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2024-10-10T07:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5207983#M592411</link>
      <description>&lt;P&gt;It's not quite optimal - not much I can do about it - maybe send the&lt;A href="https://cs.co/ise-wish" target="_self"&gt; Cisco BU a message via this link&lt;/A&gt; to express your opinion - they do read these things. I am pretty sure other folks have written a small script that runs on Windows to disable the wireless if LAN is connected, and vice-versa - if there's a will, there's a way ...&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2024 21:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5207983#M592411</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-13T21:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208004#M592414</link>
      <description>&lt;P&gt;This is how the Windows supplicant works and ISE has no visibility or control over it. The solution is using Group Policy to disable the Wireless connection when the Wired interface is connected.&lt;BR /&gt;&lt;A href="https://woshub.com/disable-wi-fi-when-ethernet-cable-connected/#:~:text=You%20can%20configure%20this%20behavior,Wi%2DFi%20when%20on%20Ethernet" target="_blank"&gt;https://woshub.com/disable-wi-fi-when-ethernet-cable-connected/#:~:text=You%20can%20configure%20this%20behavior,Wi%2DFi%20when%20on%20Ethernet&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This is also the default behaviour of the Cisco supplicant deployed when using the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/Cisco-Secure-Client-5/admin/guide/b-cisco-secure-client-admin-guide-5-0/configure_nam.html" target="_blank" rel="noopener"&gt;Cisco Secure Client Network Access Manager (NAM)&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2024 21:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208004#M592414</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-10-13T21:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208250#M592427</link>
      <description>&lt;P&gt;Hi, we have already configured GPO to minimising connections, so once employee connects to docking station, windows automatically disconnect wifi. We must test it to find out if it not harm any application.&lt;/P&gt;
&lt;P&gt;Regarding NAM module - our cisco distributor told us, that currently is much better to use Windows supplicant instead of NAM, because NAM causes a lot of troubles, so we skipped it, but we do not know how it works if its good or not. What is general opinion on NAM?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 10:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208250#M592427</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2024-10-14T10:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3 - licensing and one device wired and wireless at same time</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208453#M592434</link>
      <description>&lt;P&gt;I used to configure NAM for a few customers and that was mainly to provide EAP chaining (EAP-FAST) authentication. However, nowadays Windows can natively support that with TEAP. In addition to that NAM provides a tool to manage the network connections on the endpoint, for instance, if you don't want to allow an endpoint to add a new SSID or manipulate the network access settings, NAM can help with that. Please take a look at this link for more details about NAM:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect49/administration/guide/b_AnyConnect_Administrator_Guide_4-9/configure_nam.html" target="_blank"&gt;Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.9 - Configure Network Access Manager [Cisco Secure Client (including AnyConnect)] - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 12:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-licensing-and-one-device-wired-and-wireless-at-same-time/m-p/5208453#M592434</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-14T12:56:45Z</dc:date>
    </item>
  </channel>
</rss>

