Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other troubleshooting best practices.

Labels

Forum Posts

Hi Experts,My Customer has Profiling enabled on the Prod ISE deployment and are correctly profiling Aruba AP's using MAB not Dot1x as the auth method.Customer is concerned that if the MAC address of the AP's spoofed would it be used on any device lin...

nadeekha by Community Member
  • 1931 Views
  • 1 replies
  • 0 Helpful votes

HI All, just a quick question related to the bug https://tools.cisco.com/bugsearch/bug/CSCux72796 as per suggest, after changing the authorisation to static and upgrade to 2.0 can we then change it back to dynamic? thanks in advance Lance

Hi All ,  I need expert advice , I am an ACS 5.6 with fallback authentication configured , there is no issue in terms of configuration on NAD . What is strange is , once I try to login via AD credentials it works fine however , if I enter admin crede...

samahmad by Community Member
  • 601 Views
  • 6 replies
  • 0 Helpful votes

Hi,I will be upgrading an ISE deployment from 1.2 to 1.4, and have some questions around the process for HA IPNs (running 1.2.1):1. As the latest ISE software version for IPNs is 1.2.1, there is no software upgrade required for the IPNs?2. Would you ...

dvan by Cisco Employee
  • 1258 Views
  • 2 replies
  • 2 Helpful votes

Profiling Question:   I have a question about profiling.  I understand that it is used with ISE to make authz decisions based on what ISE can determine the endpoint is.  Profiling is used to help ISE learn this.  Few questions about profiling:   SNMP...

Will Kerr by Frequent Visitor
  • 663 Views
  • 0 replies
  • 0 Helpful votes

Customer wants to setup a static one page web page that says "You shouldn't be here, contact xxx for more information". The goal is to identify employees trying to use company computers on the guest network. They have ISE 1.4 detecting these systems ...

Tim Baum by Cisco Employee
  • 2985 Views
  • 2 replies
  • 0 Helpful votes

Hi experts,I have a Use Case for ISE 2.0 and MDM integration. The customer wants to allow BYOD devices (PEAPMSCHAP) and also MDM managed devices (PeapMschap)How can we avoid the BYOD devices to hit the MDM query rule the first time? And at the same t...

josgarza by Frequent Visitor
  • 3664 Views
  • 9 replies
  • 1 Helpful votes

HiThe ISE documentation for 1.3 states that 3395 and 3495 appliances are supported as admin and MnT nodes for a large ISE deployment, but does not specify any requirements for PSNs in a large deployment.Can 3355 appliances be used as PSNs in a large ...

gtilburg by Cisco Employee
  • 1605 Views
  • 7 replies
  • 0 Helpful votes

Hi All, we have a financial customer who is looking at deploying ISE for 60K concurrent endpoints with 2 x Admin, 2 x MnT and 8 x PSNs. They would like to get some guidance on sizing for additional storage for retaining the logs for up to 7 years. I ...

lekang by Cisco Employee
  • 2077 Views
  • 4 replies
  • 0 Helpful votes

Hello,We are currently running ISE 1.4 Patch 5 (soon to go to 2.0) along with the Cisco WLC 5508 7.4.140.0.  We have a mandate to turn off our wireless during non business hours.  Currently, I have a script that runs to shut/no shut the switchport wh...

__Beth__ by Level 2
  • 1419 Views
  • 3 replies
  • 0 Helpful votes