collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Author Topic: ISE and Re-image Desktops  (Read 13110 times)

Offline Unibog

  • Cisco Newbie
  • *
  • Posts: 9
  • Reputation: 1
  • Certification: N/A
ISE and Re-image Desktops
« on: September 19, 2013, 11:46:44 AM »
Hi Everyone,

I'm wondering how you handle re-imaging desktops and running ISE on the network. Currently the helpdesk biggest beef with ISE on the network is they have to bring the PC back to their area to re-image a PC on a port that isn't running ISE.

Wondering if someone has built a MAB policy to handle corporate desktops before they are put on the domain and get all the GPO's.

Thanks

Offline adecisco

  • Cisco Newbie
  • *
  • Posts: 96
  • Reputation: 10
  • Discovering new solution is sweet!
    • http://adeolaade.blogspot.com/
  • Certification: N/A
Re: ISE and Re-image Desktops
« Reply #1 on: September 19, 2013, 05:45:47 PM »
Here I think MAB is the way to go. For authentication MAB with identity sequence pointed to endpoint. While Authorization policy for MAB will be based on condition that meet with minimum requirements for the endpoint to have access to dns, dhcp and ports necessary to communicate with AD and GPO. After the machine is re-image and with possible reboot the dot1x can take over.

Hope this help a bit.
Technology makes life easy but I hope the same technology will not send man back to stone age!

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: ISE and Re-image Desktops
« Reply #2 on: September 19, 2013, 09:35:52 PM »
Agree with adecisco, without 802.1x enable, your only other option is MAB. You can temporarily add the PC MAC address to an Endpoint Group and create and Authorization policy to allow just enough access for the PC to be re-imaged. The problem I can see is the person who does the re-image probably does not have access to ISE to add the MAC address so it might take coordination between the two parties.

Offline Unibog

  • Cisco Newbie
  • *
  • Posts: 9
  • Reputation: 1
  • Certification: N/A
Re: ISE and Re-image Desktops
« Reply #3 on: September 20, 2013, 06:47:57 AM »
Thanks for the answer guys. When I come up with a solution I'll post it here as I think a lot of people run into this.

 

SimplePortal 2.3.7 © 2008-2024, SimplePortal