<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSK  without MAC address in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394283#M228796</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to get an update on this topic in case changes have occurred in later ISE versions. As with the original poster of this topic, I have a similar situation where a customer would like to rationalise a number of PSK services using iPSK, however, they don't have a complete list of devices &amp;amp; MAC addresses as these are 3rd systems that come on the network as and when.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally if iPSK would allow any MAC address to connect as long as they had the valid PSK, then this would tick the box. I have seen the onboarding iPSK portal with iPSK Manager, which looks really good, but does not fit my customer requirement this time. The customer could look to run reports on the clients connecting to the wireless services via Prime Infrastructure and capture the MAC addresses over time, but this could take time too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, is it possible to allow ISE with iPSK Manager to allow any MAC address to connect as long as it has the valid PSK, and then perhaps iPSK Manager then registers that MAC for future connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I am after an onboarding process without the need for the client or the customer to onboard their devices &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2021 19:23:22 GMT</pubDate>
    <dc:creator>igaffine</dc:creator>
    <dc:date>2021-04-27T19:23:22Z</dc:date>
    <item>
      <title>IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926131#M30001</link>
      <description>&lt;P&gt;I would like to use IPSK&amp;nbsp; and I undestrood it works like this:&lt;/P&gt;&lt;P&gt;-I will configure one only common SSID&lt;BR /&gt;-user who will connect to IPSK_SSID and use PSK_123 &amp;nbsp; will be connected to VLAN&amp;nbsp; 123&lt;BR /&gt;-user who will connect to IPSK_SSID and use PSK_456&amp;nbsp;&amp;nbsp; will be connected to VLAN&amp;nbsp; 456&lt;/P&gt;&lt;P&gt;-user who will connect to IPSK_SSID and use PSK_789 &amp;nbsp; will be connected to VLAN&amp;nbsp; 789&lt;/P&gt;&lt;P&gt;And this will be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is not clear to me is: before any user will be able to use PSK_XXX&amp;nbsp; do&amp;nbsp; I need to know&amp;nbsp; his&amp;nbsp; MAC address?&lt;/P&gt;&lt;P&gt;Is it really mandatory to know their mac address&amp;nbsp;&amp;nbsp; before they will be able to connect to the IPSK&amp;nbsp; SSID ?&lt;/P&gt;&lt;P&gt;Is there any way to bypass this with a wildcard that acceprt any mac and checks only&amp;nbsp; PSK&amp;nbsp; to decide to admit or not the clients?&lt;BR /&gt;My goal is to admit all clients that have the correct PSK &amp;nbsp; because (for many reasons)&amp;nbsp; I'm not able to produce a coplete database of all mac address they have now and particularly I'm not able to foresee what mac they will have in the future.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you in advance for your help&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 18:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926131#M30001</guid>
      <dc:creator>Emiliano Luca</dc:creator>
      <dc:date>2021-07-05T18:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926243#M30002</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Yes, you do. There´s no wild card for mac address as it can change significantly according with the vendor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This link below will drive you very very well on this configuration, including RADIUS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ripplesinharmony.wordpress.com/2019/03/11/implementing-cisco-ipsk-with-ise/" target="_self"&gt;https://ripplesinharmony.wordpress.com/2019/03/11/implemen&lt;/A&gt;&lt;A href="https://ripplesinharmony.wordpress.com/2019/03/11/implementing-cisco-ipsk-with-ise/" target="_self"&gt;ting-cisco-ipsk-with-ise/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 13:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926243#M30002</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2019-09-18T13:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926697#M30003</link>
      <description>&lt;P&gt;Correct you need to add their MAC addresses to your RADIUS server before they can connect. No wildcards unfortunately.&lt;/P&gt;&lt;P&gt;Keep an eye out as Cisco was talking about releasing something around on boarding IOT devices for this use case to save having to manually adding every MAC address. This was mentioned at MFD4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 05:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/3926697#M30003</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-09-19T05:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394283#M228796</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to get an update on this topic in case changes have occurred in later ISE versions. As with the original poster of this topic, I have a similar situation where a customer would like to rationalise a number of PSK services using iPSK, however, they don't have a complete list of devices &amp;amp; MAC addresses as these are 3rd systems that come on the network as and when.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally if iPSK would allow any MAC address to connect as long as they had the valid PSK, then this would tick the box. I have seen the onboarding iPSK portal with iPSK Manager, which looks really good, but does not fit my customer requirement this time. The customer could look to run reports on the clients connecting to the wireless services via Prime Infrastructure and capture the MAC addresses over time, but this could take time too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, is it possible to allow ISE with iPSK Manager to allow any MAC address to connect as long as it has the valid PSK, and then perhaps iPSK Manager then registers that MAC for future connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I am after an onboarding process without the need for the client or the customer to onboard their devices &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 19:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394283#M228796</guid>
      <dc:creator>igaffine</dc:creator>
      <dc:date>2021-04-27T19:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394408#M228803</link>
      <description>You can just create a catch all rule for end devices that are in the default endpoint group. This way you allow the devices and also capture the device mac address. &lt;BR /&gt;</description>
      <pubDate>Tue, 27 Apr 2021 23:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394408#M228803</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2021-04-27T23:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPSK  without MAC address</title>
      <link>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394581#M228816</link>
      <description>&lt;P&gt;Hi Scott, Thanks for your reply. Is that default group in iPSK Manager? My example would be migrating three SSIDs for three different 3rd parties, each having different PSKs. We would create one SSID with iPSK, and then tell the 3rd parties to connect to that with their old PSK information. Therefore this catch all could see clients connecting with three different PSKs. Would that work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, we would give them a new PSK and then tell them to use the iPSK onboarding process. But ideally we are looking at a way of doing this without iPSK Manager, as the customer is not comfortable with an unsupported platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I correct in assuming that wildcard MACs are still not allowed on ISE (as per Haydn's response)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any news on whether iPSK Manager is being integrated into ISE?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR, Ian&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 08:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ipsk-without-mac-address/m-p/4394581#M228816</guid>
      <dc:creator>igaffine</dc:creator>
      <dc:date>2021-04-28T08:04:25Z</dc:date>
    </item>
  </channel>
</rss>

