08-14-2017 09:09 AM
I have recently setup the ISE/JAMF MDM Network Integration and everything was going great with using JAMF as my MDM in ISE policy until I came to my newly issued MacBook Air that depends on a 3rd party USB NIC for wired 802.1x. ISE queries JAMF and finds that the MAC address of the USB NIC is not the JAMF primary or secondary for the MacBook. This would of course be true being this is a USB NIC and could be utilized on any machine corporate or not. ISE then incorrectly sees the MacBook as MDM non-compliant. In testing, if I temporarily set the JAMF secondary MAC address to that of the USB NIC ISE is satisfied that the MacBook is an MDM compliant device and allows 802.1x to continue. I feel like I am missing something here, but I am not sure what. How do I configure this so that ISE checks the machine against the MDM and not simply just the USB NIC?
Thank you!
Solved! Go to Solution.
08-14-2017 01:14 PM
The issue is that the client identifier as revealed by RADIUS over LAN is the MAC address of connected device. In your case, this is the USB NIC. This may not be the same NIC that was used during MDM registration and thus a mismatch in device tracking. Recommend engage Cisco sales team so they can raise issue with ISE PM for update on possible resolution in future. I can forward thread to PM as well, but helps to have customer names attached along with impact.
/Craig
08-14-2017 01:14 PM
The issue is that the client identifier as revealed by RADIUS over LAN is the MAC address of connected device. In your case, this is the USB NIC. This may not be the same NIC that was used during MDM registration and thus a mismatch in device tracking. Recommend engage Cisco sales team so they can raise issue with ISE PM for update on possible resolution in future. I can forward thread to PM as well, but helps to have customer names attached along with impact.
/Craig
08-17-2017 09:56 PM
I had same requirement for one of my customer. I also learn this through experience and abolished the plan for checking MAC address of MAC air endpoint in MDM when they are coming through wired.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide