cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1530
Views
5
Helpful
2
Replies

ISE Policy / CDP Attributes

neteng1
Level 1
Level 1

I am sending CDP attributes to ISE during endpoint authentication. I am struggling to use these attributes in an authorization policy. I want a policy that matches if cdpCachePlatform contains 'Phone'. So far, the policy does not match.

Screenshot from 2022-01-25 16-00-21.png

This is the policy I created

Screenshot from 2022-01-25 16-06-12.png

This is the dictionary I created.

Screenshot from 2022-01-25 16-10-20.png

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

You mention in another post "I want to avoid authenticating phones to ISE because it requires a plus license for profiling". Do you have the Plus license enabled?

The feature you are trying to use also leverages information from Profiling, so you would need the Plus/Advanced license enabled.

The CDP information is learned from the Profiling probes (likely sent by Device Sensor on the switch to ISE via the RADIUS probe).

View solution in original post

2 Replies 2

Greg Gibbs
Cisco Employee
Cisco Employee

You mention in another post "I want to avoid authenticating phones to ISE because it requires a plus license for profiling". Do you have the Plus license enabled?

The feature you are trying to use also leverages information from Profiling, so you would need the Plus/Advanced license enabled.

The CDP information is learned from the Profiling probes (likely sent by Device Sensor on the switch to ISE via the RADIUS probe).

Ah ok, thank you, I was not aware of that.

It may seem simple to assume that since voice voice vlan assignment works so well locally that you could bypass authentication for voice devices, but I have not found that to be the case.