10-18-2018 07:47 AM
I have never seen domain joined Macs get the AD information set from the AD profiler. Is there a technical reason for this? The DHCP hostname is the computer name just like a Windows device. If I take the hostname and do a lookup in ISE for hostname$ it works which is exactly what ISE does for Windows machines. Is this supposed to work?
Thanks.
Solved! Go to Solution.
10-18-2018 01:19 PM
Yes, here is my example for macOS and Linux. It matches what is shown for the computer object in AD:
AD-Fetch-Host-Name HOWON-MAC$
AD-Host-Exists true
AD-Join-Point AUTHC.NET
AD-Last-Fetch-Time 1539893492193
AD-OS-Version 10.14
AD-Operating-System Mac OS X
AD-Fetch-Host-Name ubuntu-desktop$
AD-Host-Exists true
AD-Join-Point AUTHC.NET
AD-Last-Fetch-Time 1539876555069
10-18-2018 01:36 PM
10-18-2018 01:13 PM
It works the same way. Only caveat is that currently ISE profiling policy doesn't utilize any non-Windows attributes with AD probe. But, one could craft a condition and add it to existing Linux or macOS profiles.
10-18-2018 01:14 PM
So you are saying the AD host exists flag should be set correctly? If we aren't seeing that then this is a bug that we need to engage TAC on?
10-18-2018 01:19 PM
Yes, here is my example for macOS and Linux. It matches what is shown for the computer object in AD:
AD-Fetch-Host-Name HOWON-MAC$
AD-Host-Exists true
AD-Join-Point AUTHC.NET
AD-Last-Fetch-Time 1539893492193
AD-OS-Version 10.14
AD-Operating-System Mac OS X
AD-Fetch-Host-Name ubuntu-desktop$
AD-Host-Exists true
AD-Join-Point AUTHC.NET
AD-Last-Fetch-Time 1539876555069
10-18-2018 01:24 PM
For what it's worth Paul, I have a tac case open because domain joined windows machines aren't always being profiled as such. It's a 2.4 deployment and we did not see the same issue on 2.1.
Haven't been able to get one of these machines from the field for testing so the case hasn't progressed. It appears to be a low occurrence, but it's still happening.
10-18-2018 01:29 PM
10-18-2018 01:31 PM
Yes, it only works with DHCP. Tracking with CSCve59881.
10-18-2018 01:36 PM
10-18-2018 01:41 PM
I'll look in to both. It's entirely possible that an ip helper could also be missing where we are seeing this.
One of the downsides to thousands of switches, config validation seems to suffer.
10-18-2018 01:47 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide