Personal devices on a corporate network
When supporting personal devices on a corporate network, you must protect network services and enterprise data by authenticating and authorizing users (employees, contractors, and guests) and their devices. Cisco ISE offers tools that enable employees to use personal devices securely on a corporate network.
Guests can automatically register devices when logging in to the Guest portals. They can register additional devices up to the maximum allowed for their guest type. The portal configuration assigns these devices to endpoint identity groups.
Guests can add personal devices to the network by running the native supplicant provisioning (Network Setup Assistant) or by adding devices to the My Devices portal. You can create native supplicant profiles. These profiles determine which native supplicant provisioning wizard to use based on the operating system.
Native supplicant profiles are not available for all devices. Users can use the My Devices portal to add these devices manually, or administrators can configure Bring Your Own Device (BYOD) rules to register these devices.
End-user device portals in a distributed environment
Cisco ISE end-user web portals depend on the Administration, Policy Services, and Monitoring personas to provide configuration, session support, and reporting.
-
Policy Administration node (PAN): Configuration changes that you make to the users, devices, and end-user portals are written to the PAN.
-
Policy Service node (PSN): The end-user portals run on a PSN. A PSN handles all session traffic, including network access, client provisioning, guest services, posture, and profiling. If a PSN is part of a node group, and one node fails, the other nodes detect the failure and reset any pending sessions.
-
Monitoring node (MnT node): The MnT node collects, aggregates, and reports data about the end-user and device activity on the My Devices, Sponsor, and Guest portals. If the primary MnT node fails, the secondary MnT node automatically becomes the primary MonT node.
Global settings for device portals
You can configure these general settings for the BYOD and My Devices portals:
-
Employee Registered Devices: Enter the maximum number of devices that an employee can register in Restrict employees to. By default, this value is set to 5 devices.
-
Retry URL: Enter a URL that can be used to redirect the device back to Cisco ISE in Retry URL for onboarding.
After you configure these general settings, they apply to all BYOD and My Devices portals that you set up for your company.

Feedback