01-18-2024 04:53 AM
Hello,
I have a question regarding BYOD and randomized MAC addresses.
I have implemented Single SSID BYOD flow. Users are getting onboarding, ISE is the CA server and it sends certificates to them. I have found that in certificate template I can choose to use not only MAC address but MAC + GUID too.
After successful onboarding, if MAC address changes ISE cannot identify device as BYOD Registered and users are redirected to BYOD onboarding portal again.
My question is - how can I configure ISE to use GUID as device identifier ?
Solved! Go to Solution.
01-18-2024 02:12 PM
@llomjaria , the short answer is, you can't. See the following recent discussion on the similar topic.
https://community.cisco.com/t5/network-access-control/byod-solution-for-mac-randomized-endpoints/td-p/4994234
01-21-2024 01:44 PM
No, the workaround to mitigate issues with MAC randomization is to remove authorization conditions that use the MAC address from your policies as per this Field Notice.
01-18-2024 05:18 AM
check some reference discussion :
https://community.cisco.com/t5/network-access-control/ise-byod-mac-onboarding/m-p/3836332
01-18-2024 05:25 AM
Thanks for the reply!
I have checked provided discussion but it is not related to my issue.
01-18-2024 02:12 PM
@llomjaria , the short answer is, you can't. See the following recent discussion on the similar topic.
https://community.cisco.com/t5/network-access-control/byod-solution-for-mac-randomized-endpoints/td-p/4994234
01-19-2024 12:31 AM
@Greg Gibbs Thank you for the response!
So user should register the same device every time MAC changes?
01-21-2024 01:44 PM
No, the workaround to mitigate issues with MAC randomization is to remove authorization conditions that use the MAC address from your policies as per this Field Notice.
01-18-2024 06:44 AM
Did you check that the clients actually get the right attributes in their certificates pushed by ISE? if not, you might need to make sure that you associated the certificate profile to the client provisioning policy profile. If both are correct, please share your authorization rules for review.
01-18-2024 07:03 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide