Hi Tim,
From what I understand Clearpass is using the RADIUS accounting packet information it recieves from the WLC to determine a profile for the device. If the device is catagorized as a SmartDevice, we want to keep it off of our Corp SSID. As I mentioned, this works as expected however there are a few devices (iPhones for example) that are connecting and should not be based on the enforcement policy rule, a common factor here is that there are no accounting logs for these sessions therefore our theory is they are not getting profiled at all and are skipping over the rule we have defined to keep them off. So, my question would be if this is a known issue is there something that can be addressed on the Clearpass side of this equation to improve things. Right now DHCP profiling isn't going to be an option, given the complexity of our environment and limitation of the Cisco WLC only being able to support 2 IP Helper addresses for DHCP relay.