06-14-2019 10:04 AM
Since ISE gains the most sensor data about an endpoint after it has received its DHCP lease, I need this to occur before I can create a well designed profile for the new device.
What I don't want to do is open up DHCP to any device that plugs into the network.
What I am hoping to do is plug in a new device, choose it from the endpoints list and manually assign an authz policy that will give it DHCP. Once ISE fully profiles the device, then I can use those attributes to build a well designed policy.
Is there a function in ISE to manually assign an authz policy to an endpoint?
Solved! Go to Solution.
06-14-2019 11:33 AM
06-14-2019 11:33 AM
06-17-2019 12:28 AM
There are a number of ways you can achieve this but just to name a few:
- Prer-defined Identity Group with the list of mac addresses
- Match based on mac OUI
- Match based on NDGs , NAS IP adress , NAS port type and the list goes on...
06-17-2019 07:13 AM
Thank you
I am familiar with creating policies to match these objects, I was hoping there was a "manual override" in a sense where I could choose the device from the endpoints list and manually assign the authz policy temporarily.
07-01-2019 09:15 PM
I believe you already got the idea. ISE does not work that way. The closest is in Mohammed al Baqari's response.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide