cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1372
Views
5
Helpful
2
Replies

Authenticate Ubuntu with ISE 2.4

Reuven Elkabetz
Level 1
Level 1
Hi , I would like to authenticate Ubuntu WS with Dot1x and I successfully did with with Identities. I configure the WS under identities and configure under AD the WS as computer account. a member of this computer account is another AD group that assign special VLAN under policy-set table. This working fine. I would like to add under policy set a variable of operating system type that will verify if it is Ubuntu or Windows and allow it to connect. Any idea how I can do it or where I can find document regarding it? Thanks, Reuven
1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Start here: https://community.cisco.com/t5/security-documents/ise-community-resources/ta-p/3621621#Visibility

It sounds like you want to Profile the Ubuntu machines and allow certain Authorizations based upon the profiled machine type.

You'll need Plus licenses for this.

View solution in original post

2 Replies 2

Charlie Moreton
Cisco Employee
Cisco Employee

Start here: https://community.cisco.com/t5/security-documents/ise-community-resources/ta-p/3621621#Visibility

It sounds like you want to Profile the Ubuntu machines and allow certain Authorizations based upon the profiled machine type.

You'll need Plus licenses for this.

Mike.Cifelli
VIP Alumni
VIP Alumni

As @Charlie Moreton stated you can do so via profiling endpoints based on your device sensors (NADs).  Just note that if you decide to use profiled groups as an authz condition to push policy you will need ISE Plus licenses on top of your ISE Base licenses.  Essentially if you push policy to an endpoint based on a profiled group one endpoint would consume one base and one plus license.  Another option you could play with is using any of the following conditions:

EndPoints:OperatingSystem Equals XXXX

SessionDevice-OS Equals XXXX

Good luck & HTH!