cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1671
Views
35
Helpful
5
Replies

Block Cisco AV attribute via authorization rule in ISE

ryan14
Level 1
Level 1

Is it possible to block a device trying to connect via AnyConnect with the Cisco AV pair mdm-tlv=device-platform=apple-ios? I have created an AuthZ rule which denies Cisco·cisco-av-pair 'contains' apple-ios, but it never matches the rule.

1 Accepted Solution

Accepted Solutions

@ryan14 this is the bug I recall was related to this issue, it started working after applying the patch.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz55258

 

View solution in original post

5 Replies 5

@ryan14 yes, that looks like the correct acidex attribute, I've used it before with win clients.

 

Look in the live logs or take a packet capture of the authentication process and confirm exactly what attributes is sent by the client.

Yeah I copied pasted an attribute from the live logs but my rule must be wrong. Here is a screen shot (it matches the rule below it):

 

Capture2.PNG

Capture1.PNG

  

@ryan14 I cannot test your exact scenario currently, but this screenshot is from my notes - it uses the same AVP but I've included mdm-tlv=device-platform= which you do not appear to have.

 

1.PNG

My memory is not 100%, but I think when I tested this it did not work and I had to patch ISE (probably 3.0), then it worked.

OK Thanks. I tried including the full string from the live logs but didn't make any difference. I also tried including contains 'apple' but didn't match either. I am running 2.7 so, will try this again after upgrading to 3.x.

@ryan14 this is the bug I recall was related to this issue, it started working after applying the patch.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz55258

 

Review Cisco Networking for a $25 gift card