04-02-2019 08:11 AM - edited 02-21-2020 11:04 AM
We are trying a PoC to integrate Cisco ISE with Jamf Pro.
We have communication with the Jamf Pro server, have developed the authorization profile for unregistered & registered devices & can see that devices are getting the right policy but in the case of unregistered devices the redirect is not working.
Can anyone see what is missing?
Auth Profile
Auth Policy
Jamf Network Integration
WLC ACL
04-02-2019 09:53 AM
04-02-2019 11:37 PM
If you mean the enrol URL then no, it is also possible to browse to any web pages. The ACL I took from the Cisco documentation.
04-05-2019 05:15 AM
Is there anyone who can provide some insight on this?
04-05-2019 06:26 AM
I usually push back on doing MDM enrollment via ISE, but a few thoughts come to mind:
04-05-2019 07:51 AM
Thanks for your reply.
Yes the client seems to be getting the ACL applied from the WLC but the URL doesn't look right it should be the FQDN/enrol
It looks like the URL its getting ISE in the auth profile.
04-05-2019 07:53 AM
The client is not FlexConnect? You didn't show the top part of the client details so I couldn't tell if the client was local or flex.
04-05-2019 07:54 AM
Its not flexconnect no.
04-05-2019 07:56 AM
Nevermind, I see hits on your ACL so I assumed the client must be local mode and not FlexConnect. Your ACL looks to only be redirecting traffic to internal web sites. You are testing by going to internal web sites?
04-05-2019 07:58 AM
No the website is hosted by Jamf but uses our domain name.
04-05-2019 08:33 AM
04-05-2019 08:38 AM
Ah I see, you could be correct. I took the ACL configuration from Cisco documentation but didn't understand why the first line allows everything out.
How would you suggest the ACL be changed?
04-05-2019 09:13 AM
04-05-2019 08:57 AM
Yes your right. I have tried going to an internal page from the client & I hit rule 8 & I'm redirected but the page fails to load.
The full URL looks like this & fails.
I can get to https://myapple.bathspa.ac.uk/enrol from the client though.
04-05-2019 09:46 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide