<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wifi access depending on Endpoint name in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320959#M597788</link>
    <description>&lt;P&gt;if you dont use WLC 9800&amp;nbsp;&lt;BR /&gt;try add phone username/password to different internal identity store&amp;nbsp;&lt;BR /&gt;then in Authz match this internal identity&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
    <pubDate>Fri, 15 Aug 2025 11:04:52 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-08-15T11:04:52Z</dc:date>
    <item>
      <title>Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320943#M597785</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;Im sure this will be a simple one to answer. Using ISE 3.2 to authenticate users on wifi. Setting up a new policy for iphones/ipads for corporate users. We want them to not be able to connect to this SSID with a personal device. We will be using 802.1x, with AD authetication so users log in with their own credentials, and this is all working fine.&lt;/P&gt;&lt;P&gt;Trying to add an additional condition of saying "Only allow the user to connect if their iphone name contains XXX" but cant seem to be able to do this. We have everything else setup in terms of certificates (The devices auto trust the certificate so a bit pointless!), usernames etc but you can connect personal phones to the SSID and want to limit this to only our corporate devices&lt;/P&gt;&lt;P&gt;Any help and advice gratefully received&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 11:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320943#M597785</guid>
      <dc:creator>Daniel-Clark</dc:creator>
      <dc:date>2025-08-15T11:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320947#M597786</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1908766"&gt;@Daniel-Clark&lt;/a&gt;&amp;nbsp;perhaps use Username CONTAINS XXX in an authorisation policy rule, i.e., -&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1755254326815.png" style="width: 516px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250326i72894C2F76EA4C53/image-dimensions/516x92?v=v2" width="516" height="92" role="button" title="RobIngram_0-1755254326815.png" alt="RobIngram_0-1755254326815.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Or if using username/password, match on the AD group the devices are a member of.&lt;/P&gt;
&lt;P&gt;Or perhaps there is another unique attribute in the user's account attribute/certificate that can distinguish between the devices?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 11:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320947#M597786</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-15T11:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320956#M597787</link>
      <description>&lt;P&gt;if you use WLC 9800 then try use iPSK&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 10:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320956#M597787</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-15T10:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320959#M597788</link>
      <description>&lt;P&gt;if you dont use WLC 9800&amp;nbsp;&lt;BR /&gt;try add phone username/password to different internal identity store&amp;nbsp;&lt;BR /&gt;then in Authz match this internal identity&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 11:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320959#M597788</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-15T11:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320976#M597789</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1908766"&gt;@Daniel-Clark&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I think the best way to solve this is to authenticate corporate devices by machine certificate pushed from MDM/through group policy. This is a far stronger method of authentication than authenticating by device name + AD credentials. See the following configuration guide:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 12:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320976#M597789</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-08-15T12:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Wifi access depending on Endpoint name</title>
      <link>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320990#M597790</link>
      <description>&lt;P&gt;So, for what you want to do, I really don't know of a way other than what&amp;nbsp;Torbjørn&amp;nbsp;mentioned and use an MDM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure the scale you are on, so there are some things you could do, but a lot of manual work. Such as making a group of just the MAC addresses of the devices, but with random MAC and such can be a pain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Couple questions to ask before making it a lot of work for yourself. Do these iPhones/iPads get internal access, and if so why? and if they don't, then do you care if they connect a personal device?&lt;/P&gt;&lt;P&gt;I was looking through mine and even though you can get profiling with DHCP, I can't find the device name picked up. So I don't see anything for an option by device name.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 13:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wifi-access-depending-on-endpoint-name/m-p/5320990#M597790</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2025-08-15T13:21:28Z</dc:date>
    </item>
  </channel>
</rss>

