04-13-2021 12:26 PM
I have a Cisco ISE 2.6 running MAB authentication only. The list of authorized MACs has been uploaded to ISE. However, after deleting one MAC address, the endpoint still authenticates and successfully connects to the network. I checked logs and its saying that the endpoint MAC is found on the internal endpoints idstore. I am not sure why it would still authenticate even after the MAC has been removed from the authorized list.
Thanks.
Solved! Go to Solution.
04-13-2021 12:56 PM
Does the MAC address appear back in the Context Visibility > Endpoint GUI view? ISE will add an endpoint by default if you are providing an access accept result back to the network device.
When you look at the live log, which authentication and authorization rule is it hitting, check the result of that authorization rule.
04-13-2021 12:56 PM
Does the MAC address appear back in the Context Visibility > Endpoint GUI view? ISE will add an endpoint by default if you are providing an access accept result back to the network device.
When you look at the live log, which authentication and authorization rule is it hitting, check the result of that authorization rule.
04-15-2021 09:54 AM
Yes that is exactly what happened. Thank you for pointing me to the right direction.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide