cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
686
Views
5
Helpful
1
Replies

MAC lookup on PSN during Posture

ggmeza1983
Level 1
Level 1

Hi, I am configuring posture on cisco ise 2.6 with 4.x CM.

We have a problem when a client connect with anyconnect. We have on radius live log the wireless mac address, but on the log, we can check that ise psn make a lookup mac session from another net link, specifically the mac of virtual lan generated by microsoft windows direct. This generate the message discovery not detected when try the posture scan check.

How can i solve this issue? we have configured as priority lan, then wifi. Maybe any configuration on nam can solve this?

 

Thanks.

Thanks in advance.

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

I don't know what "4.x CM" is. Please be specific.

I don't understand your description of the problem. You are doing wireless but I don't understand the MAC lookup. If you are trying to do MAC Authentication Bypass (MAB) it should be done on the PSN directly. I don't understand what you mean that it is doing a lookup for the MAC session on another net link.

Posture would be a totally separate issue.

You need to include actually ISE LiveLog details and probably policy details you are expecting if it is not matching.

We do not have enough information which is probably why nobody else has responded for 2 weeks.

Consider calling TAC to help with your questions.

How to Ask The Community for Help 

This

View solution in original post

1 Reply 1

thomas
Cisco Employee
Cisco Employee

I don't know what "4.x CM" is. Please be specific.

I don't understand your description of the problem. You are doing wireless but I don't understand the MAC lookup. If you are trying to do MAC Authentication Bypass (MAB) it should be done on the PSN directly. I don't understand what you mean that it is doing a lookup for the MAC session on another net link.

Posture would be a totally separate issue.

You need to include actually ISE LiveLog details and probably policy details you are expecting if it is not matching.

We do not have enough information which is probably why nobody else has responded for 2 weeks.

Consider calling TAC to help with your questions.

How to Ask The Community for Help 

This