05-02-2014 01:34 AM - edited 03-10-2019 09:41 PM
Hello all,
I currently deploying a Cisco ISE for my wireless network and I would like to split my WLAN in two different "authorization profile" : Guest and Corporate.
For the moment, I use my active Directory to authenticate users and profiling to authorize device with the hostname. I would like to classify by domain name with DHCP probe but I can't because there is alway a DHCP message response with the domain name given by the DHCP server, do you have a solution to separate device with domain name or with other attributes ?
Thanks in advance for your answer!
Solved! Go to Solution.
05-02-2014 05:15 AM
you can create different authorization profile based on the identity group they belong to , therefore , make two profiles based on two Identity group ( guest/ corporate AD users ) and assign them different access. refer ISE 1.2 config guide.
05-02-2014 05:15 AM
you can create different authorization profile based on the identity group they belong to , therefore , make two profiles based on two Identity group ( guest/ corporate AD users ) and assign them different access. refer ISE 1.2 config guide.
05-02-2014 06:52 AM
Thanks for your answer salodh,
I've already done two authorization profiles (Guest and corporate) based on rule using Active Directory and profiling condition but I would more profiling conditions (not only hostname) to split clearly corporate and guest devices.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide