<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE filtering mobile devices. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3211535#M905427</link>
    <description>&lt;P&gt;Thank you, Marvin, for your reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the best solution devices that are not owned by a company, and are a BYOD?&lt;/P&gt;
&lt;P&gt;This would be my main goal is how can I filter BYOD devices vs&amp;nbsp; CORP. In a way where users are able to give some sort of "data", "MAC" or some kind of unique identifier for mobile devices, That I can filter on?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2017 12:37:25 GMT</pubDate>
    <dc:creator>Jordan Taylor</dc:creator>
    <dc:date>2017-11-06T12:37:25Z</dc:date>
    <item>
      <title>Cisco ISE filtering mobile devices.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3210774#M905421</link>
      <description>&lt;P&gt;Hello to one and all.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working on a project, need to restricted access to a network. end users that our domain joined, as well as mobile users, can access the network.&amp;nbsp; i.e "users that have the Cisco any connect app" using AD credentials.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be best practice for restricting access for the mobile users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;MDM Server&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;CA Certs&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;GPO&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These are some methods I have come across.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any input in the would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3210774#M905421</guid>
      <dc:creator>Jordan Taylor</dc:creator>
      <dc:date>2020-02-21T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE filtering mobile devices.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3210807#M905424</link>
      <description>&lt;P&gt;If you have an MDM that's the best option for restricting mobile device access. It does require ISE Apex licensing to integrate with your MDM (via API).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mobile users on BYOD or remote corporate laptops won't normally be covered by your MDM (though I believe Meraki Systems Manager might do this).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GPOs of course only apply to domain machines. That said, it's pretty simple to check for domain membership in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificates for end users and machines work OK but if you don't have a CA it may be more than you want to take on to establish the whole PKI infrastructure internally.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2017 02:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3210807#M905424</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-04T02:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE filtering mobile devices.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3211535#M905427</link>
      <description>&lt;P&gt;Thank you, Marvin, for your reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the best solution devices that are not owned by a company, and are a BYOD?&lt;/P&gt;
&lt;P&gt;This would be my main goal is how can I filter BYOD devices vs&amp;nbsp; CORP. In a way where users are able to give some sort of "data", "MAC" or some kind of unique identifier for mobile devices, That I can filter on?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 12:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3211535#M905427</guid>
      <dc:creator>Jordan Taylor</dc:creator>
      <dc:date>2017-11-06T12:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE filtering mobile devices.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3211939#M905429</link>
      <description>&lt;P&gt;Well you start with looking for domain membership (remote laptops corporate-owned). They get one AuthZ policy result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, if you have an MDM and Apex license, check for corporate mobile devices. They get another AuthZ result (or maybe the same one depending on your policy).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anything that doesn't match one of the above gets a more restrictive AuthZ.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 03:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-filtering-mobile-devices/m-p/3211939#M905429</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-07T03:23:26Z</dc:date>
    </item>
  </channel>
</rss>

