08-13-2012 01:10 PM - edited 03-10-2019 07:25 PM
I use ISE only for profiling ( no posturing ) and it's L3 adjent with other devices (wlc).
for iphones and stuff I only need OUI=Apple and i'm good ( no need to go deeper), but I'm having problems identifiying Laptops, they show up as unknown, eventhough I use the DHCP option.
Is there any quick rule to identify them, DHCP or Radius or whatever?, or maybe a redirect to ISE http somehow but I don't want them to posture and all that(including NAC Agents), I just want to identify them and then assign appropriate access.
08-13-2012 01:24 PM
Are they not being profiled as a workstation? When you check the endpoint what does policy match does it show? Do you see any of the dhcp attributes in the endpoint attribute list?
Also, you can build a posture redirect policy but do not create any client provisioning rules, what this does it will redirect the client, gather the http user agent string, then it will profile the user and issue coa.
The user will see a message that lets them know a profile doesn't match but the can retry their request n 60 seconds.
thanks,
Sent from Cisco Technical Support iPad App
08-13-2012 01:35 PM
EndPointSource RADIUS Probe
08-13-2012 01:40 PM
this is for iphones:
Total Certainty Factor 40
EndPointSource RADIUS Probe
dhcp-client-identifier | 01:ec:85:2f:be:56:dd |
dhcp-message-type | DHCPREQUEST |
dhcp-parameter-request-list | 1, 3, 6, 15, 119, 252 |
FOR PCS
Total Certainty Factor 0 and no DHCP eventhough i have set DHCP = class-identifier CONTAINS MSFT
08-13-2012 01:43 PM
Are you seeing this with all your workstations? Do you have a static ip configured on the client? Also is the windows client wireless just like the apple device?
Sent from Cisco Technical Support iPad App
08-13-2012 01:48 PM
Well I've tried two IBM laptops so far with different OUIs and they show up as unknown, no static ip on the client pc.
not sure what you mean by:
Also is the windows client wireless just like the apple device?
08-13-2012 01:50 PM
How are they joining the network....wireless or wired?
Sent from Cisco Technical Support iPad App
08-13-2012 01:52 PM
Everything is wireless same ssid, NO DHCP PROXY, added ISE_IP_ADDRESS in the ip-helper config.
08-13-2012 01:55 PM
Is the dhcp probe enabled under the deployment settings?
Sent from Cisco Technical Support iPad App
08-13-2012 01:57 PM
Yes on both, primary/secondary, i've got secondary as a primary monitor node.
08-13-2012 02:11 PM
One way to troubleshoot this is to use the tcdump utiltity to see if the dhcp packet is hitting the ISE node. See if you can set the filter for 'ip host sviofvlan' and then run the capture after reassociating to the network. Then see if the mac address of you client and dhcp requests comes to ISE.
Thanks,
Tarik Admani
*Please rate helpful posts*
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide