cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1506
Views
0
Helpful
4
Replies

MAC book authentication with Cisco 3.0 with JAMF

Team,

We have been trying to work on authentication/authorization for our MAC books with the Cisco ISE 3.0.
The MAC books are registered(or call it enrolled) with JAMF.

How best can we ensure that JAMF can be used as a MDM to authorize the MAC books?

 

We went through various combinations like registered status, MDM servers reachable etc. but no success.

It can be that the parameters that are being passed by the MAC book are not complaint with anything the JAMF is sending or the JAMF is knowing.

 

Any kind of help or suggestion here would be of extreme help.

 

Our end goal here is to make the MAC book authentication as seamlessly as possible to the network.

 

 

Regards,

N!

4 Replies 4

marce1000
VIP
VIP

 

 - You may find this document useful : https://community.cisco.com/kxiwq67737/attachments/kxiwq67737/discussions-network-access-control/455447/2/JAMF%20Integration%20with%20ISE%20as%20MDM.pdf

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi Marce,

We have tried all these steps. The challenge is that we cannot get any of the Attributes working.

We are not sure if this is even begin received from the JAMF.

 

Regards,

N!

- Does the Jamf have some logging facilities and or log files that you can
examine ?


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Greg Gibbs
Cisco Employee
Cisco Employee

A couple things here...

The MDM API used prior to ISE version 3.1 (APIv2) uses the MAC address of the endpoint as the only identifier to check against the MDM server. You should confirm that the MAC address that ISE sees from the endpoint is what is captured by JAMF as part of enrolment. If the MacBooks are using a dongle for Wired connections and/or the Wifi connection is using a randomised MAC address, it will break the MDM checks. There is an enhancement in ISE 3.1 to mitigate both of these issues, but it also requires the MDM vendor to support the new MDM APIv3 (which I don't know if JAMF has implemented yet).

If you're using the non-randomised Wireless connection and have confirmed that JAMF has registered the same MAC address that ISE sees from the authentication, you will probably need to setup the debug logs as per this document and review the ise-psc.log to see what response ISE is getting from the MDM server.

If this is an urgent issue, please open a TAC case to investigate further.