12-08-2020 03:43 AM
if I created two rules one is "android Samsung" the other is "android LG" with each matching device id with "android" and giving it both certainty of 30, what will happen if I have several devices rules with the same certainty value?
12-08-2020 03:57 AM
Hi @baselzind
It depends on the device, you might find when the device is profiled it may match the cisco provided profiles for "Android" or "Samsung-Device", which may mean your custom profiles are not matched. The certainty factor is cumulative, so you'd need to ensure you specify a high value.
If 2 profiles have the same certainty factor and a device matches both, then there is no tie-breaker logic. You'd need to provide additional attributes to ensure ensure the endpoint is matched to the correct profile.
Reference:
12-08-2020 04:40 AM
12-08-2020 04:52 AM - edited 12-08-2020 04:55 AM
No, it won't remain as unknown, ISE has enough information to profile the endpoint, it will be profiled using one of your custom profilers.
As per the reference I provided - Note: There is currently no tie-breaker logic if an endpoint matches two different profiles with the same TCF. In such cases, it may be necessary to augment the CF for a specific rule to bias the selection of one profile over another.
In other words, ensure the profilers are unique.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide