Very interesting thread. Can you tell me – how can ISE differentiate between a new/unknown computer owned by an employee and/or the organization, which you WANT to load the NAC client on, and a guest that you might want to give Internet access to but...
Patrick, I agree with Tarik that Cisco should enhance ISE in this way. Other NAC products can do this with no problem. No user involvement is needed, no agents are needed, no HTTP browser is needed. For example, here is the host-based information tha...
ForeScout sells an alternative NAC product to Cisco ISE. It works with or without 802.1x, so it is typically easier to implement than Cisco's product, and it does a better job of working with unknown/unmanaged devices that don't have 802.1x agents al...