cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
379
Views
1
Helpful
5
Replies

AD prob incorrect data

Hello,

I have ISE 3.1.0.518 patch 8. I have a problem that ISE is not fetching the correct attribute information for MacOS. My Macs are not joined to my Windows domain, but ISE finds AD attributes for my Mac but completely wrong. They detect that it is a Windows with another host name. I deleted the Endpoint Mac and bad data comes back. How to fix this?

Endpoint Profile: Apple-Device

AD-Operating System: Windows 10

AD-Fetch-Host-Name: wrong host name

1 Accepted Solution

Accepted Solutions

The AD prod is activated to be able to make rules depending on which group or OU a computer finds itself in.
But I think I found my problem. ISE relies on reverse DNS entry, and I notice that I have a problem at this level. My PTR entries do not match the DNS entries.

View solution in original post

5 Replies 5

Do you have the need for the AD probe?  Why is it enabled to start with?  

The AD prod is activated to be able to make rules depending on which group or OU a computer finds itself in.
But I think I found my problem. ISE relies on reverse DNS entry, and I notice that I have a problem at this level. My PTR entries do not match the DNS entries.

Yeah without properly functioning reverse records you will see issues like this with the AD probe.  I would argue active authentication based on machine certificates and looking up OU based on the derived machine name from the certificate is a much better approach for checking group/OU membership than relying on the AD probe.

Interesting, I'll look into that. Do you happen to have any documentation on this? I'm quite new to ISE. Thanks for your help

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html#toc-hId-133117567

I would also suggest going through some ISE training to learn about authorization policy logic, etc.  I would also suggest working with your Cisco Account SE and your preferred Cisco Partner of choice to also help with ISE deployment and policy creation.