<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE for Mobiles in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355995#M88492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi andy&lt;/P&gt;&lt;P&gt;this will help to solve my problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i couldn't find the condition "P&lt;SPAN style="font-size: 10pt;"&gt;ostureApplicable" in the autherization policys rules , could you help me where can i find this....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Reyad&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-collapse: collapse; list-style: none; float: left; width: 20px;"&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jan 2014 20:22:54 GMT</pubDate>
    <dc:creator>Reyad Safi</dc:creator>
    <dc:date>2014-01-27T20:22:54Z</dc:date>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355991#M88488</link>
      <description>&lt;P&gt;Hello every body...&lt;/P&gt;&lt;P&gt;I have ISE appliance integrated with Active Directory to authenticate the users , and i have WLC integrated with the ISE also.&lt;/P&gt;&lt;P&gt;the integration done successfully , and now any user want to access the network through the WIFI ( Dot1x) he should use his AD credintials and if he Compliant he get a full access , if non compliant he go to the quarantine vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my problem is the mobiles , there's some users need to access the WIFI using the personal mobiles using the AD credintials , and i need to bypass the posturing for mobiles only.&lt;/P&gt;&lt;P&gt;in other words , i don't need to check if the devise is compliant or non compliant for the mobiles only , while i need this feature for laptops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;note : i have only 1 SSID &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any suggestions for this case....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reyad&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355991#M88488</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2019-03-11T04:19:21Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355992#M88489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Reyad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution for the Mobile devices is to enable the profiling, by enabling the profiling, you can categorize the access for all the smart devices, and you can combine them with Wireless_dot1x so all the users can authenticate the access using the AD username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general, the ISE does not have NAC agents or posture for mobile devices, so you can build an authorization policy based on profiling and authentication, and you can put it on top of the policies so if the ISE detects mobile phone access then the authentication will be dot1x against the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Ahmad. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jan 2014 04:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355992#M88489</guid>
      <dc:creator>Ahmad Murad</dc:creator>
      <dc:date>2014-01-26T04:12:51Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355993#M88490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Ahmad&lt;/P&gt;&lt;P&gt;in my case , i noticed that i have only 2 profiled categories.&lt;/P&gt;&lt;P&gt;one for workstations , and the other for ip phones ,,, but unfortunately the Smart phones and mobiles have been recognized as workstations which is become useless when i configure the policey for the profiled devise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i need is to configure a policey for any not-windows devise &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can i configure the profiling feature for these devises &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any suggestions ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reyad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 16:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355993#M88490</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-01-27T16:39:28Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355994#M88491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Reyad, you need to create an Authorisation Policy that matches "PostureApplicable Equals No" &lt;SPAN style="text-decoration: underline;"&gt;above&lt;/SPAN&gt; the Authorisaton Policies you have defined for PostureStatus Equals Compliant and PostureStatus Not_Equals Compliant.&lt;/P&gt;&lt;P&gt;Any devices that are not capable of posture assessment (e.g. your mobile devices) will match this rule and bypass the NAC process before hitting the rule you are currently matching.&lt;/P&gt;&lt;P&gt;This should work fine as long as all other Authorisation Policies are correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 18:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355994#M88491</guid>
      <dc:creator>andyirving</dc:creator>
      <dc:date>2014-01-27T18:31:31Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355995#M88492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi andy&lt;/P&gt;&lt;P&gt;this will help to solve my problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i couldn't find the condition "P&lt;SPAN style="font-size: 10pt;"&gt;ostureApplicable" in the autherization policys rules , could you help me where can i find this....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Reyad&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-collapse: collapse; list-style: none; float: left; width: 20px;"&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 20:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355995#M88492</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-01-27T20:22:54Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355996#M88493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Inorder to have definetions for broader range of endpoints like smartphones , PDAs, please use profiler feed service. It would ensure the device profiles database is updated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 05:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355996#M88493</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-01-28T05:35:14Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355997#M88494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can find it under Endpoints as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/0/2/178205-noncompliant.png" alt="noncompliant.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 09:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355997#M88494</guid>
      <dc:creator>andyirving</dc:creator>
      <dc:date>2014-01-28T09:17:54Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355998#M88495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Andy and sorry for bothering you again...&lt;/P&gt;&lt;P&gt;but i couldn't find the EndPoint within my drop list in the autherization policey page.&lt;/P&gt;&lt;P&gt;do you think its related to ISE IOS version , or i need to do some configuration in some where to have EndPoint.&lt;/P&gt;&lt;P&gt;My ISE version is : &lt;SPAN style="font-size: 10pt;"&gt;Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.1.0.665&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/7/0/2/178207-drop-list.jpg" alt="drop-list.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 19:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355998#M88495</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-01-28T19:04:36Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355999#M88496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Reyed, the Endpoint policy was added in ISE 1.1 MR1 I believe, you will need to upgrade to see this.&amp;nbsp; I would strongly recommended upgrading to the latest release of ISE anyway as it is much improved on version 1.1.0.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 19:13:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2355999#M88496</guid>
      <dc:creator>andyirving</dc:creator>
      <dc:date>2014-01-28T19:13:16Z</dc:date>
    </item>
    <item>
      <title>ISE for Mobiles</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2356000#M88497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you Andy for your help....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reyad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 19:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-for-mobiles/m-p/2356000#M88497</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-01-28T19:17:39Z</dc:date>
    </item>
  </channel>
</rss>

