cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
636
Views
0
Helpful
4
Replies

ISE issues with OS X High Sierra

tucch
Level 1
Level 1

Our authorization results of machines with OS X High Sierra are as follows:

 

- Sometimes recognized correctly as High Sierra and allowed on to our internal network as designed

- Sometimes recognized as mobile devices that belong on the personal non-corporate network (but still provided an internal IP)

 

No other OS is acting like this when authorizing. Should we be looking at policies or OS X settings?

1 Accepted Solution

Accepted Solutions

You need to look at the data collected by profiling to determine what is making it a mobile device vs. High Sierra.  How are you even getting them profiled as Sierra devices?  The default profile only has User Agent matching which means you would have to bring the device into an ISE portal to collect that information or span Internet traffic to ISE (not feasible).

View solution in original post

4 Replies 4

tucch
Level 1
Level 1
I should add that this is on wireless only.

You need to look at the data collected by profiling to determine what is making it a mobile device vs. High Sierra.  How are you even getting them profiled as Sierra devices?  The default profile only has User Agent matching which means you would have to bring the device into an ISE portal to collect that information or span Internet traffic to ISE (not feasible).

I also thought a client provisioning portal can collect user agent data? So if you have any posture redirects to a client provision portal you should be gathering that data also. 

 

Are these corporate devices? Are they added to a windows Domain? If so you can gather Mac OS X operating system from a domain query and build a profile based on that info. 

Any portal in ISE you bring a client into will automatically collect HTTP header data. I have brought mobile devices into portals before just for the sole purpose of collecting HTTP data for more accurate profiling, but that is pretty rare.