Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello Team,
We are using full-blown ISE (no ISE-PIC) for usual 802.1x (EAP-TLS-based Machine auth mainly) and now configuring same ISE deployment for PassiveID to distribute User-IP mappings from AD (via ISE AD Agents) towards WSA and FMC. We are n...
Team,I know that CSCve39167 has been confirmed by Apple as being an issue on their side (?) and they are planning to "fix" it.We are struggling with Apple CNS and dual SSID flow while being unable to use DNS ACL due to old APs and not being able to u...
Hello Team,Does anybody know if it is possible to somehow get PAN role (Active/Standby) programmatically (via API) or manually via CLI (SSH session)?Use case is: I have an API script running every night to do certain stuff on ISE (clean up Guests in ...
Hello All,Thanks to Jason and others, solution described in ISE Guest Self-Registration phone number as the username is working perfectly in ISE 2.1The major issue I cannot find a way to solve is the following: Customer wants to allow up to 3 device...
Hello Andreas.
There is no solution as such if this is your requirement:
- use a separate ISE-PIC deployment for passive ID (but remember that you only can associate one ISE instance with FMC or Stealthwatch, for example, so may not work in your en...
Hi Hsing-Tsu,
Thank you, would be interesting to hear what team says.
I see this as a possible/frequent use-case especially with WSA 11.7/FMC/etc integration in place - always is appealing to deploy/keep 1 ISE instance instead of deploying 2 sets o...
Hello Jason,Yes, these have been read and well understood, thank you!.Still my Customer would benefit from more precise issue description and timeframes/timelines from Apple side so if you could post that additional information there (fixed versions/...
Arne's method is the suggested one, I think.Meanwhile, for those of us who are not yet on 2.2 , the following will work: try to create user via API.While primary will respond with HTTP 201, Secondary will tell you:<!DOCTYPE html><html> <head> <title...