cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
676
Views
0
Helpful
3
Replies

ISE problem with BYOD smart solution...

jiyoung Kim
Level 1
Level 1

Hi

I did all configurations in the byod smart solution.

and I was curious.....how they idenfity OS of devices...

I wanted to use 'Session:Devices-OS' ... but it seems not to work..

Also,

I want to profile self-registered devices. so if someones register their iPad2 or iPhone,

I want them to profiled in Mobile under the RegisteredDevices ( I was able to create a group called Mobile under the RegisteredDevices).

and I want to use this identity group when I create authorization rules.

is there any way to do it??


Hope this is clear enough to be understood.

thank you.

Best regards.

Justin

3 Replies 3

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

The following thread covers the answer you are after.

https://supportforums.cisco.com/message/3744919#3744919

Basically the device-os attribute is satisfied through posturing or using nmap. Not through http/dns/dhcp profiling.

thanks,

Tarik Admani
*Please rate helpful posts*

then how does ise know client's OS on client provisioning phase....?

in the smart solution, they have different resources..

can we use this information for authorization ??

You may need to open a tac case for confirmation, but I think the ISE learns the information from the user agent string that is learned from when the client is redirected to the ISE portal to download the nac agent.

Thanks,

Tarik Admani
*Please rate helpful posts*