08-17-2016 07:58 AM
Hi All,
Since we are running ISE version 2.1 we are seeing a huge increase of the amount of learned endpoints.
After investigation it looks like these are endpoints are/were connected to our hotspot SSID but the user didn't accept the AUP.
As soon as a user accept the AUP the endpoint becomes a member of an endpoint identity group which we purge at certain times.
Because the solution is implemented in more than 150 high density locations we're facing about more 20000 endpoints this month which are not part of a scheduled purge operation.
We tried to create a purge policy including never purge rules for certain endpoint Identity groups and one general purge rule which did not have an endpoint identity group as condition. This policy was purging the 'unkown' endpoints but also the endpoints which are member of an endpoint group to which a never purge policy is be applied.
Does anyone see a solution for this?
Thanks in advance,
Jan-Willem Molenaar
08-17-2016 09:30 AM
Are you saying that this doesn't work for you?:
08-17-2016 11:33 AM
Well, 'Unkown' in your case is an endpoint Identity group and the devices are not a member of this group. Therefore it won't work. But If you remove the condition 'Unknown' all endpoints will be purged including the one which are part of the never purge rules.
08-17-2016 12:57 PM
An endpoint will be dynamic assigned according to its endpoint attributes collected and to unknown if no attribute presents able to move it to another group or no static assignment.
A better solution might be to try preventing such endpoints getting into the endpoint store in the first place. Is possible to dedicate PSNs for such hot spot use and disable specific profiling probes, such as RADIUS and DHCP probes? Also note that AireOS 8.3 has this new feature -- Enabling RADIUS NAC on a WPA and WPA2-PSK WLAN
08-17-2016 01:34 PM
Endpoint won't be dynamicly assigned since no profiling license is installed. Its also not required because it is just a basic hotspot functionality. They also don't appear as member of the unknown group.
I would love to know how to prevent them getting into the endpoint database. All profiling probes are disable and we've dedicated PSN's in the DMZ. We can't avoid users from connecting to our hotspot. If we can get them to the endpoint group unknown I would be able to purge them.
08-19-2016 03:51 PM
Yes this approach using WPAPSK will also protect the ip address pool from exhaustion as well
08-17-2016 01:43 PM
By no profiling licenses, I assume you meant no ISE advanced or plus licenses. Anyhow, this might be either a bug or some strange configuration issue so I would suggest to log a TAC case to investigate why endpoints getting added to the endpoint store without any enabled profiling probes and not accepting AUP in ISE 2.1.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide