cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
771
Views
1
Helpful
2
Replies

Guest Endpoint not switching Identity Group Assignment CWA

ajc
Level 7
Level 7

Running ISE 2.7 patch 7. Question: I have a device that was previously connected to a 802.1x SSID and directly assigned to the endpoint group = unknown, later I manually assigned it to an endpoint group = testing. So my question is: If I have device automatic registration in the guest portal I am using for CWA which points to the Guest Endpoint Group, should my device switch from "testing" to the "guest" endpoint group or not?. So far my tests show it is not working. profiling is not enabled (it should but I do not make that call, someone preferred the "cheap" way so I am wondering if this feature not enabled is the reason that it does not work). 

1 Accepted Solution

Accepted Solutions

Rodrigo Diaz
Cisco Employee
Cisco Employee

hello @ajc , yes it's expected that the assignment remain statically where you configured the endpoint.

So far there are 2 types of endpoint assignment on ISE the default that you have is dynamic , unless you assign an endpoint to a matching group and  provided you don't have profiling within your ISE the devices will be classified as unknown, now while assigning endpoints to a group what you do is to change an attribute on the endpoint that turn off this dynamic clarification , hence the endpoint group cannot be assigned anymore dynamically to GuestEndpoint group for any other process on ISE , please review for your reference  https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_assetvisibility_endpoints.html 

RodrigoDiaz_0-1678566764746.png

 

View solution in original post

2 Replies 2

Rodrigo Diaz
Cisco Employee
Cisco Employee

hello @ajc , yes it's expected that the assignment remain statically where you configured the endpoint.

So far there are 2 types of endpoint assignment on ISE the default that you have is dynamic , unless you assign an endpoint to a matching group and  provided you don't have profiling within your ISE the devices will be classified as unknown, now while assigning endpoints to a group what you do is to change an attribute on the endpoint that turn off this dynamic clarification , hence the endpoint group cannot be assigned anymore dynamically to GuestEndpoint group for any other process on ISE , please review for your reference  https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_assetvisibility_endpoints.html 

RodrigoDiaz_0-1678566764746.png

 

I will open a TAC case for my 2nd question. thanks