cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1284
Views
0
Helpful
0
Replies

ISE - Is it posible to assign the device to different Endpoint Identity Groups depend on the Policy Set's Rule??

EricLiu05720
Level 1
Level 1

Hi all,

 

I am a Cisco newbie, Hope someone can help on this.
I created a captive portal(self-registration portal) with AD integration.

The self-registration is disabled and it keeps the basic authentication function only.

The current captive portal will push different radius attributes (Filter-ID) to the AP(Meraki MR) to assign the group policy(801.2x policy) to different user's devices depends on the OU of the AD user. But we found that users need to log in again if the disconnected the WiFi.

I would like to let the user reconnect the WiFi automatically so I think we may add the device, which signed in, to specified Endpoint Identity Groups when the first time login of the users. Just like the Default Hotspot Guest Portal did.

we can add more rules to check whether the mac address of the device is in the specified Endpoint Identity Groups then push the correct filter-id.

But I found that only one Endpoint Identity Group can be assigned for the devices if using only one captive portal which makes my plan fail.

Is it possible to assign the device to different Endpoint Identity Groups depend on the Policy Set's Rule??

Sorry for my poor English.

0 Replies 0