<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Andy, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631528#M74814</link>
    <description>&lt;P&gt;Hi Andy,&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Were you able to figure this out?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Oct 2016 16:54:23 GMT</pubDate>
    <dc:creator>derrick.ray1</dc:creator>
    <dc:date>2016-10-04T16:54:23Z</dc:date>
    <item>
      <title>ISE Endpoint Identity Group assignment for 802.1x clients</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631527#M74813</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I'm using ISE 1.3 to 802.1x authenticate AD PC's (machine and user with Anyconnect NAM) and to profile/mab IP Phones, printers, APs etc.&lt;/P&gt;&lt;P&gt;Phones are profiled (EndPointSource of SNMPQuery Probe) and are placed automatically in the correct Identity Group.&lt;/P&gt;&lt;P&gt;AD PC's aren't profiled and are listed under Endpoints withthe Enpoint Profile of "unknown"&lt;/P&gt;&lt;P&gt;To place AD PC's into a particular Identity Group, I created a Radius Profiling Policy to match on the Framed-IP-Address. This works well with the AD PC appearing in the correct Identity Group (with EndPointSource of RADIUS Probe).&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A phone (profiled with EndPointSource of SNMPQuery Probe) consumes a Plus licence but an AD PC ("profiled" with EndPointSource of RADIUS Probe) does not - is this correct?&lt;/LI&gt;&lt;LI&gt;Authenticated 802.1x AD PC's have other attributes (like AD-Host-Resolved-DNs) that I'd like to use to assign PC's to an Identity Group. I can't use these attributes with any of the ISE profilers - is there a way to assign an 802.1x authenticated client to an Identity Group at the authorisation stage rather than use the profiler?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631527#M74813</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-03-11T05:23:47Z</dc:date>
    </item>
    <item>
      <title>Hi Andy,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631528#M74814</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Were you able to figure this out?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 16:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631528#M74814</guid>
      <dc:creator>derrick.ray1</dc:creator>
      <dc:date>2016-10-04T16:54:23Z</dc:date>
    </item>
    <item>
      <title>Hi Derrick. No, I was moved</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631529#M74815</link>
      <description>&lt;P&gt;Hi Derrick. No, I was moved off this work and didn't get it resolved. I'll be looking at ISE again soon so I'll post any findings.&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 06:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631529#M74815</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2016-10-05T06:25:15Z</dc:date>
    </item>
    <item>
      <title>The phone consumes a Plus</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631530#M74817</link>
      <description>&lt;P&gt;The phone consumes a Plus license because you are using a profile to authenticate/authorize the connection. Technically, the PC consumes a Plus license as well but only during the profiling process. It is released after profiling if you do not use the profiling information in an authorization rule.&lt;/P&gt;
&lt;P&gt;Endpoint groups are based on profiling or guest assignment&amp;nbsp;(which is kind of like the probe based profiling). I have not seen any way to assign a 802.1x authenticated device to an endpoint group outside of profiling.&lt;/P&gt;
&lt;P&gt;ISE 2.1 has an AD profiling probe built in if you want to build an endpoint group based on the AD join point of the PC. It was not available in previous ISE releases. You can use that to profile AD joined computers and automatically add them to an endpoint group. You can find more information here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200553-Configure-ISE-2-1-Profiling-Services-bas.html&lt;/P&gt;
&lt;P&gt;Using that and the resulting endpoint group in an authorization rule would consume a Base and Plus license (base for authentication, Plus for the profiling based authorization).&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 14:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-identity-group-assignment-for-802-1x-clients/m-p/2631530#M74817</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-10-05T14:37:17Z</dc:date>
    </item>
  </channel>
</rss>

