cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
468
Views
0
Helpful
5
Replies

ISE Not Recognized some Devices.

JRGC
Level 1
Level 1

Hi guys.

I have a cisco ISE solution implemented in my network.


I have a some issues using profiling, because some devices aren't recognized when used the same version of system operation. For example windows 7,8 and 8.1.

Some devices are recognized for another parameter example card wireless or  some case show devices Intel and not windows version.

I don´t have a MDM solucions,  only I have ISE profiling

 

What would be the reason ?

 

Regards,

5 Replies 5

George Stefanick
VIP Alumni
VIP Alumni

Hello 

 

I struggled with this very issue myself. I learned and needed remind myself that ISE profiling is not an exact science. I also tested each and every profile widget to see what value each provided. DNS, radius, DHCP, http redirect etc. 

I found that each of these profile pieces have their own corky work around. Your profiled library of devices at best is a best guess. 

 

The best way to profile a device as a company issued device put a cert on it. You won't know what bee of windows but you will know it's a company asset. For mobile mdm is the way to go. 

 

If if your simply trying to break down windows version you might try http redirect. 

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________

thank you for your input.

Now I have policy with type of device and active directory users group.

 

What kind of license  will need ?

How create cert on cisco ISE and on computer ? you have a guide?

 

Regards

can you chat about what your policy is ? Are you trying to only allow corp devices on the network ? 

 

This is is a key driver for how you create policy and design. 

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________

Sure, I have three WLANs created all with ISE security


1. Corporate Users ( Laptops )
2. Smartphones 
3. Guest  Users

George Stefanick
VIP Alumni
VIP Alumni

Is your policy only allowing corp devices on the WLAN or corp users. Corp users can use their AD but use their personal devices. This is very important piece .. 

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________
Review Cisco Networking products for a $25 gift card