05-15-2018 08:26 AM
Hi,
One of my customer is facing an issue when on of the PC required IT maintenance.
Summary of issue faced:
Unable to authenticate the pc after technical support activities.
Exact cases to reproduce the error:
2- Formatting the pc will lead to losing the connectivity as well.
3- Maintenance team need to engage ISE team in each time they need to do PC maintenance which is not practical.
Needed Solution:
To find a way for helpdesk representatives to be able to connect to the domain controllers and DHCP servers while doing the maintenance for the targeted pc.
Thank you for your support..
05-15-2018 10:36 AM
You can do MAB with restricted access as a workaround. Also, you could do some type of internal portal that lets the technician choose a PC to put in a “maintenance” endpoint group and while that thing is in the maintenance group it does MAB and gets restricted access.
05-15-2018 10:41 AM
Hi George,
do you have a reference that showing how to do MAB and/or how to do this internal portal to be accessed by PC technician?
Thanks..
05-15-2018 10:53 AM
I would advocate setting up a Temporary Bypass Portal concept using the MyDevices portal. I set this up on every ISE install to allow Help Desk and Desktop team to add a MAC address into a temporary bypass condition so they can reimage/troubleshoot an issue. The temporary white list gets purged out every night.
Basic steps:
05-15-2018 10:55 AM
Also I have written a executable that uses the ISE APIs to automatically add the MAC address of the machine the executable is run on to the temp bypass whitelist. Customers have added this to their build sequence. Most customers just use the temp bypass portal though.
05-15-2018 11:06 AM
How has the radius token been working well for you in the mean time? I've had a client asking for authz rules on the my devices portal for over a year. It is a much needed feature to be able to use AD/LDAP groups to provide my devices portal access.
The guest reg portal has it, why can't this one Cisco?
05-15-2018 11:13 AM
I used the RADIUS callback on every ISE install. I probably have 30+ installs using it and my colleagues us it as well.
05-15-2018 10:43 AM
While not a very elegant solution, this only works if the technicians are physically at the machine. Create a static endpoint ID group, assign technicians usb nic's into the group while documenting who owns them. When they need to re-image a PC they can utilize the usb nic to gain network access.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide