We're rolling out Cisco ISE to all our Ethernet ports.
On any port where ISE has been turned on, Macs display this at the login screen: Network accounts are unavailable
For users with existing mobile accounts on those Macs, this isn't a problem because they can log in even without network access. Once they are logged in (and the CCAAgent posturing client does its thing), they have full network & internet access.
But anyone without a locally cached account simply can't log in.
This makes me think the Macs are unable to reach our Active Directory Domain Controllers.
(As a temporary workaround, we've kept an ISE-free Ethernet port at the help desk; we have users log in once using that port, so that their accounts get cached. But this isn't a good long-term solution.)
Our Cisco guy (a Mac user, but not a Mac expert) says everything is open internally and they should be able to reach the DCs. I thought maybe Macs are "phoning home" to Apple as a check for network access, but he said access to any host at apple.com domain is enabled by default.
Any ideas on how to fix this?
