07-19-2019 01:25 AM
Dear all,
I recently deployed ISE 2.6 in a dispersed mode, and until now everything runs smoothly.
I have a requirement from business about giving access to the LAN to some "unmanaged and exotic" devices like scanners/3d printers, and so on...
Most of these just don't support dot1x or CWA, and they are also on the network only for a few days/weeks, during staging phase.
I am looking for a friendly way for the enduser to register these devices with their MAC addresses on the ISE, into the correct endpoints' group. Else, the security team can be surrounded from requests every day...
Any idea how to achieve that ? or maybe a different approach?
Thanks for your help ;)
Solved! Go to Solution.
07-19-2019 02:10 AM
07-19-2019 09:07 AM - edited 07-19-2019 09:39 AM
Yes. That is also an option provided the customer is ok with giving access to ISE on port 443 from the VLAN the users will be residing. Also, any user part of a specific user group can edit any device part of the specific endpoint group to which the access is given. For example :
Select the AD Group the user is a part of above.
Data access as follows :
Menu Access as follows :
Policy as follows :
The result will be as follows as when a user part of the AD group listed under Admin Group :
07-19-2019 02:10 AM
07-19-2019 02:35 AM
Thanks Surendra,
Last question: can I also restrict the access to these portals to only some users or group of users (like based on AD group or local ISE users) ?
07-19-2019 03:45 AM
07-19-2019 04:08 AM
Ok, I'll find another way to restrict the access to it ;)
Thanks a lot for your help !
07-19-2019 08:36 AM
You can use the API to write your own portal.
@Surendra what about using the PAN and giving access to certain groups? Its not nice like the my devices but they could also have RBAC to groups.
Another option using my devices (hasn't been validated for a while)
07-19-2019 09:07 AM - edited 07-19-2019 09:39 AM
Yes. That is also an option provided the customer is ok with giving access to ISE on port 443 from the VLAN the users will be residing. Also, any user part of a specific user group can edit any device part of the specific endpoint group to which the access is given. For example :
Select the AD Group the user is a part of above.
Data access as follows :
Menu Access as follows :
Policy as follows :
The result will be as follows as when a user part of the AD group listed under Admin Group :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide