cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
775
Views
0
Helpful
4
Replies

Can I do a profile by hostname?

fwiest
Level 1
Level 1

I am trying to create a profile rule so separate shop floor computers from office computers. They are in different AD groups by host name but I don't have the MAC in AD. Is there a way to profile them using an AD group without the MAC address?

1 Accepted Solution

Accepted Solutions

Admin/Identity Management/External identity Sources.

Select your AD and there should be a groups tab. Pull in your 2 AD groups and they should then be usable in conditions.

View solution in original post

4 Replies 4

I use host names to verify if they are on or off domain, so you should be able to do it.

Just use <AD>:ExternalGroups in your rules. Make sure you pull the groups in to ISE from your AD.

OK, I think I am not defining my group correctly. Thanks for the input.

Admin/Identity Management/External identity Sources.

Select your AD and there should be a groups tab. Pull in your 2 AD groups and they should then be usable in conditions.

hslai
Cisco Employee
Cisco Employee

What Dustin suggested would work if performing DOT1X with computer identities.