03-08-2022 12:04 PM
Is it possible to block a device trying to connect via AnyConnect with the Cisco AV pair mdm-tlv=device-platform=apple-ios? I have created an AuthZ rule which denies Cisco·cisco-av-pair 'contains' apple-ios, but it never matches the rule.
Solved! Go to Solution.
03-09-2022 07:00 AM
@ryan14 this is the bug I recall was related to this issue, it started working after applying the patch.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz55258
03-08-2022 12:35 PM
@ryan14 yes, that looks like the correct acidex attribute, I've used it before with win clients.
Look in the live logs or take a packet capture of the authentication process and confirm exactly what attributes is sent by the client.
03-09-2022 05:42 AM
Yeah I copied pasted an attribute from the live logs but my rule must be wrong. Here is a screen shot (it matches the rule below it):
03-09-2022 05:52 AM
@ryan14 I cannot test your exact scenario currently, but this screenshot is from my notes - it uses the same AVP but I've included mdm-tlv=device-platform= which you do not appear to have.
My memory is not 100%, but I think when I tested this it did not work and I had to patch ISE (probably 3.0), then it worked.
03-09-2022 06:57 AM
OK Thanks. I tried including the full string from the live logs but didn't make any difference. I also tried including contains 'apple' but didn't match either. I am running 2.7 so, will try this again after upgrading to 3.x.
03-09-2022 07:00 AM
@ryan14 this is the bug I recall was related to this issue, it started working after applying the patch.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz55258
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide