cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3193
Views
7
Helpful
5
Replies

AnyConnect/ISE UDID for Quarantine Verification

scamarda
Cisco Employee
Cisco Employee

The UDI function of AnyConnect 4.7 / ISE 2.6 mentions the UDI is shared among all AC modules and is used for ISE Posture

 

...When AnyConnect is installed on a device, it will have its own unique identifier (UDID) shared among all modules in AnyConnect. This UDID is an identifier for the endpoint and is saved as an endpoint attribute, which ensures posture control on a specific endpoint rather than on a MAC address.

 

Can the UDI be referenced in a Quarantine scenario,  meaning the user violated policy while wired and was quarantined.  Is the UDI attribute available to quarantine when the user tries to connect via wireless?  Does UDI work for other features besides Posture?

 

Thanks.

 

Sam

 

Sam

2 Accepted Solutions

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee
No. The use of the UDID with AC requires some additional scripting for use with AD and is a posture only feature.

Regards,
-Tim

View solution in original post

5 Replies 5

Timothy Abbott
Cisco Employee
Cisco Employee
No. The use of the UDID with AC requires some additional scripting for use with AD and is a posture only feature.

Regards,
-Tim

Hi Tim,

 

Is this still the case with ISE 3.0? 

 

 

hslai
Cisco Employee
Cisco Employee

Yes.

toyip
Cisco Employee
Cisco Employee

Hi all,

 

Got a customer looking to use the UDID in the posture condition. Do you have a working example of how this is done as as Tim stated above?

arravik2
Cisco Employee
Cisco Employee

Hi To do that i believe UDID is added as part of description field in the AD for the endpoint or user @hslai @Timothy Abbott  please correct me if i am wrong