<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adaptive Policy limitations in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399631#M772</link>
    <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/15353"&gt;@joey.debra&lt;/A&gt; are you referring to me as OP?  If so I wasn't trying to use IP, I wanted to use MAC address and I don't want the headache of running a RADIUS solution where I have a cloud managed network.  &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/51406"&gt;@alessandrodematos&lt;/A&gt;'s suggestion might be the way forward in the Merakiverse, unfortunately I haven't had a chance to test it yet...&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jul 2025 19:13:44 GMT</pubDate>
    <dc:creator>CMR</dc:creator>
    <dc:date>2025-07-25T19:13:44Z</dc:date>
    <item>
      <title>Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399625#M766</link>
      <description>&lt;P&gt;I was looking into using adaptive policy and it seems that objects can only be matched on CIDR.  I was wanting to use it in lieu of Smartports not being supported on any of the Catalyst based switches.  This would require matching on MAC or something else that does not seem to be supported.&lt;/P&gt;&lt;P&gt;Is there a way of putting IoT devices of a known type into a specific VLAN other than Smartports?  Or is there a plan to roll Smartports out to the C9x00 switches?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 12:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399625#M766</guid>
      <dc:creator>CMR</dc:creator>
      <dc:date>2025-07-12T12:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399626#M767</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Unfortunately none of the C9X00 switches offer smartports (and I doubt it &lt;/SPAN&gt;&lt;SPAN&gt;ever will), believe you’d need to adopt Cisco ISE into this equation to achieve &lt;/SPAN&gt;&lt;SPAN&gt;your goal.&lt;SPAN class=""&gt;  &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am not familiar enough with Cisco DNA to understand if it might offer an alternative solution but it may?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 13:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399626#M767</guid>
      <dc:creator>RWelch-USA</dc:creator>
      <dc:date>2025-07-12T13:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399627#M768</link>
      <description>&lt;P&gt;I&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/14571"&gt;@CMR&lt;/A&gt; wrote:&lt;BR /&gt;&lt;P&gt;I was looking into using adaptive policy and it seems that objects can only be matched on CIDR.  I was wanting to use it in lieu of Smartports not being supported on any of the Catalyst based switches.  This would require matching on MAC or something else that does not seem to be supported.&lt;/P&gt;&lt;P&gt;Is there a way of putting IoT devices of a known type into a specific VLAN other than Smartports?  Or is there a plan to roll Smartports out to the C9x00 switches?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Yes, using MAB with RADIUS or profiling with ISE on Catalyst C9k. On Meraki MS, also possible via MAB (but less granular, no native profiling).&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 14:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399627#M768</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-07-12T14:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399628#M769</link>
      <description>&lt;P&gt;Thanks &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/51406"&gt;@alessandrodematos&lt;/A&gt; using MAB and then selecting Access Manager and picking MAC address might do what I want.  Time to experiment!&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 16:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399628#M769</guid>
      <dc:creator>CMR</dc:creator>
      <dc:date>2025-07-12T16:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399629#M770</link>
      <description>&lt;P&gt;You could use Meraki Access Manager and the MAB feature to assign SGT tags.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Overview/Architecture_and_Example_Use_Cases#Securing_Non_802.1X_Supported_IoT.2C_OT_or_Other_Endpoints_-_MAC_Authentication_Bypass_(MAB)" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/Access_Manager/Access_Manager_Overview/Architecture_and_Example_Use_Cases#Securing_Non_802.1X_Supported_IoT.2C_OT_or_Other_Endpoints_-_MAC_Authentication_Bypass_(MAB)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 01:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399629#M770</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-07-14T01:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399630#M771</link>
      <description>&lt;P&gt;I always hated smartports on Cisco small business switches since they would destroy your network just by connecting one type of device on a port.&lt;BR /&gt;&lt;BR /&gt;However I don't really get OP's question.&lt;BR /&gt;The application of the correct tag happens only happens on IP as a last resort.  You're supposed to use a radius solution and profiling to assign the correct tag to the session because the tag itself is just an identifier that helps for policy enforcement.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 13:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399630#M771</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2025-07-25T13:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399631#M772</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/15353"&gt;@joey.debra&lt;/A&gt; are you referring to me as OP?  If so I wasn't trying to use IP, I wanted to use MAC address and I don't want the headache of running a RADIUS solution where I have a cloud managed network.  &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/51406"&gt;@alessandrodematos&lt;/A&gt;'s suggestion might be the way forward in the Merakiverse, unfortunately I haven't had a chance to test it yet...&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 19:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399631#M772</guid>
      <dc:creator>CMR</dc:creator>
      <dc:date>2025-07-25T19:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive Policy limitations</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399632#M773</link>
      <description>&lt;P&gt;I see.  Well for modern workplace kind of customers that don't want to run own server, you can use access manager as the radius solution.  that gives you 802.1x + MAB with an easy tagging method.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;However you can just put an adaptive policy tag on a switchport if you want &lt;SPAN class="lia-unicode-emoji" title=":winking_face:"&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;What I took away from the whole trustsec/adaptive policy is that the solution is meant to do away with VLAN sprawl which I really get.  Because yes I have customers with small branch sites that sport 20+ VLANs just to have some policies between them.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jul 2025 17:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/adaptive-policy-limitations/m-p/5399632#M773</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2025-07-26T17:47:15Z</dc:date>
    </item>
  </channel>
</rss>

