This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
Since ISE gains the most sensor data about an endpoint after it has received its DHCP lease, I need this to occur before I can create a well designed profile for the new device.
What I don't want to do is open up DHCP to any device that plugs into the network.
What I am hoping to do is plug in a new device, choose it from the endpoints list and manually assign an authz policy that will give it DHCP. Once ISE fully profiles the device, then I can use those attributes to build a well designed policy.
Is there a function in ISE to manually assign an authz policy to an endpoint?
Solved! Go to Solution.
There are a number of ways you can achieve this but just to name a few:
- Prer-defined Identity Group with the list of mac addresses
- Match based on mac OUI
- Match based on NDGs , NAS IP adress , NAS port type and the list goes on...
Thank you
I am familiar with creating policies to match these objects, I was hoping there was a "manual override" in a sense where I could choose the device from the endpoints list and manually assign the authz policy temporarily.
I believe you already got the idea. ISE does not work that way. The closest is in Mohammed al Baqari's response.