04-07-2017 12:45 AM
Hi,
I made a remediation setup between FP 6.2 and ISE 2.2, and it works as expected (the end device is moved into the exception policy and is remediated properly).
However, this device doesn't show up in the ANC->End Point assignment List.
I can use the EPS Unquarantine menu to remove the MAC address from the list of remediated devices, however it doesn't appear here.
Would it be a know issue in 2.2, or just a particular issue linked to my environment ?
Thanks for any comment,
jean-francois
04-07-2017 01:16 AM
Hi,
It looks like a normal behavior when assignment is done by using FMC (PxGrid).
I notice the same behavior with ISE version 2.1 and 2.2
Of course it will be nice if ISE will show this MAC list under endpoint assignment list.
So the way to see the quarantine MAC and in order to Unquarantine is by using ANC report or look at the radius log.
Nir
04-07-2017 08:10 AM
Any idea about any improvement planned in a near future ?
It looks challenging to ask an helpdesk guy to look into a radius log file to verify whether a machine has been quarantine or not ...
thanks,
jean-francois
04-07-2017 10:58 PM
Please contact ISE product management team to discuss roadmap items.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: