02-01-2017 11:25 AM
Situation: User logs off system terminating session with ISE, how can an administrator still get to the device for windows updates, etc, or to log in to the system to troubleshoot. VNC is installed on endpoints, but we can not even RDP to the endpoint.
ISE version 2.1 patch 1 and 2, AnyConnect version 4.3 with NAM and ISE Posture, DART also installed.
Solved! Go to Solution.
02-01-2017 09:34 PM
Jeffrey,
I have already responded to your question in other post here: Re: ISE 1.4 API remove stale sessions
You can use Low Impact Mode or return a default MAB-based policy that grants required access.
Craig
02-01-2017 09:34 PM
Jeffrey,
I have already responded to your question in other post here: Re: ISE 1.4 API remove stale sessions
You can use Low Impact Mode or return a default MAB-based policy that grants required access.
Craig
02-02-2017 10:23 AM
This is a good question. I think that if you have implemented machine authentication (AD Domain Joined Machines), you should be able to do this.
I have an Authorization Compound Condition (Policy > Policy Elements > Conditions > Authorization > Compound Conditions) set up like this:
Which is used in my Wired Access Policy Set (Policy > Policy Sets)
The permissions (AD-ONLY) given are set at Policy > Policy Elements > Results > Authorization Profiles. Of course, you'll need a DACL for this, too (Policy > Policy Elements > Results > Downloadable ACLs).
And that should give you the access you desire.
02-02-2017 01:51 PM
This works great on Cisco switches, but not on HP ProCurve which this customer has. cant do dacl
02-02-2017 01:55 PM
Then reference the ACL on the switch:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide