10-04-2017 10:37 AM - edited 02-21-2020 10:35 AM
Hi I'm Ivan
I have a question
Does it is possible join both technologies in one process or 2 proceess using policy to authenticate and authorize, BYOD and Profiling?
I would like to analyze BYOD together with Profiling to enforcement the access of my users when they try access using BYOD with an smartphone android or apple. I would like to enforcement that with Profiling to Apple or Android
Please can you help me with any documentacion or link?
Regards.
Ivan.
10-04-2017 08:15 PM
10-04-2017 08:19 PM
Hi, thanks you for the answer. I would like to join Dot1X + BYOD + Profiling with authen and author policies.
How can i do it?
Regards.
10-04-2017 08:29 PM
10-04-2017 08:50 PM
Hi.
But i don't understand the following.
If the policy to authenticate byod services for apple says: EAP TLS with Certificate Auth Profile, and Profiling to authenticate use MAB services for internal identity store (it was created when i configure profiling policy), how can exist both dot1x and MAB?
Regards
10-05-2017 06:37 AM
Hi
Profiling doesn't mean MAB. Profiling is based on multiple probe source like dhcp, dns, http, netflow....
Then, when your device is authenticating in dot1x, it will go through the authentication process and then move to the authorization process, right. In that authorization, no matter if it's dot1x or MAB, you can define policies based on a profil group device.
In conclusion, profiling will be used mainly in the authorization rules nothing related with MAB or dot1x that are part of Authentication rules. On ISE, on the policy-set, the authentication is done on the 1st half part of the page while authorization is the 2nd half part of page and it will be in this section where you gonna use profiling groups.
Is it more clear?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide