08-16-2018 10:25 PM
Hi,
We have deployed Wireless BYOD with dule SSID flow using NetworkSetupAssistant and also we have deployed posture check for Guest users using Cisco temporary agent which working perfectly fine.
we need to do posture check for BYOD user with duel SSID flow.
Can any one tell me is it possible to achieve this in cisco ISE 2.3 and how we can deploy Posture check for BYOD user with dule SSID flow in ISE 2.3.
Solved! Go to Solution.
08-17-2018 07:42 AM
08-17-2018 06:21 AM
08-17-2018 07:26 AM
08-17-2018 07:42 AM
08-17-2018 07:58 AM
08-17-2018 09:37 AM
08-18-2018 09:13 PM
08-20-2018 10:34 AM
It is hard to tell without knowing how the policy is structured. Typically customers would enable posture lease to skip posture if it has been done past X number of days. However, if the endpoint is skipping posture beyond the posture lease, my guess is that there is another policy rule in the policy set that is listed before the posture related rule that is causing the skipping of posture. I would suggest looking at live log and going through which policy is being matched and change the order or make changes to the policy condition so two policy rules doesn't conflict.
08-17-2018 06:59 AM
*here be dragons!*
Running posture against the miriad of devices that people will bring will be impossible. ISE only supports Windows / OSX (Linux added yet?), so BYOD folks come in with something else - netbook, tablet, smartphone, wifi enabled widget, an IOT thing, etc... it won't work. If somebody has a crazy locked-down machine it may also not work.
Admittedly I don't know the wider context of your use case / budget / network, but if you're concerned about BYOD-related security issues, you may do well to consider a secure network design, backed up by more generic and transparent security services like Umbrella and Firepower Threat Defence +ISE's Rapid Threat Containment. Services like these work regardless of device type and require no user interaction, no software to install, etc... Although you get less 'depth' (ie, less visibility 'in' to the BYO device) with this approach, you get MASSIVELY more bredth, and you avoid the faff of having to put software on people's machines, no faff with browser security issues, and so on.
08-17-2018 07:51 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide