cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

ISE 2.3 patch 2 - Policy set rule does not match rule with custom logical profile.

Rodrigo Gurriti
Level 3
Level 3

Hello,

 

Just found something odd. 

 

Custom profile for a few printers.

I then added them to a logical profile.

Created a policy for them.

 

Tested the printers, they get the profiled.

They show up on the logical profile, I can see all MAC addresses. 

They match the policy. Life is great!

 

A couple days later they don't match anymore. The policy because ISE doesn't see match the logical profile. 

Other policies using logical profile are OK

I re-did all the profile policies, logical profile and policy set. It works, but if there is a re-auth they will not match anymore.

I also noticed that the ISE cannot get information from the logical profile. 

Untitled.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

TAC does not know what is going on, but I work around by creating a policy matching on the profiled device instead of the logical profile and it works. 

 

PS. I have other custom logical profiles and they work just fine. 

 

Has anyone seen this before? 

Who Me Too'd this topic