cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
565
Views
1
Helpful
3
Replies

ISE 2.3 device admin, authentication only hits default policy.

mathech
Level 4
Level 4

Hi,

I have a few policy sets created, however when my test device authenticates it only hits the default policy.

Policy

policy.PNG

log

log.PNG

The "NetEng Global Default IOS Device" policy conditions are set for all device types and all locations. However it only hits the default. I reread through the configuration guide and everything appears to be correct. I'm scratching my head. TIA!

1 Accepted Solution

Accepted Solutions

Definitely odd, can you check to see if it just doesn't like the equals device type/location of all, and change to contains?

Seems like a bug, cause it looks like you should be hitting rule 2.

View solution in original post

3 Replies 3

Definitely odd, can you check to see if it just doesn't like the equals device type/location of all, and change to contains?

Seems like a bug, cause it looks like you should be hitting rule 2.

That was it!  Logic says EQUALS would work. But at any rate, I changed my policies to CONTAINS and it works. Many thanks, was banging my head all day.

Yeah, I think it's a bug, I thought contains may work as the device type in your log was

"Device Type#All Device Types#LAN Devices#Access Switch"