<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Try this and see if it works in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345321#M125323</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Try this and see if it works:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Dictionaries &amp;gt; System &amp;gt; Radius&amp;nbsp;&amp;gt; RADIUS Vendors &amp;gt; Cisco-VPN3000&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Add&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Attribute Name: CVPN3000/ASA/PIX7x-Group-Based-Address-Pools&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Data Type: String&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Direction: Both&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;ID: 217&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;** Do rate helpful posts **&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2014 22:32:39 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2014-06-02T22:32:39Z</dc:date>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345311#M125313</link>
      <description>&lt;P&gt;We are going to integrate ASA remote access VPN service with a new ISE 1.2.&lt;/P&gt;&lt;P&gt;The authentication is done against Active directory. After the authentication, can static IP address be assigned to a specific VPN user by ISE?&lt;/P&gt;&lt;P&gt;That means the same VPN user will always get the same IP address. Thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345311#M125313</guid>
      <dc:creator>y.lo</dc:creator>
      <dc:date>2019-03-11T03:52:47Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345312#M125314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can assign &lt;SPAN style="font-size: 10pt;"&gt;IETF-Radius-Framed-IP-Address in authorization policy. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;However if I may make a suggestion:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Unless you have only a handful of users to do it for, it may make sense to assign address-pool from ISE or perform LDAP attribute mapping on ASA itself. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In the latter case the IP addresses are maintained on LDAP server as a attributes and ASA will map it IP address. You don't want to maintain IP address DB in multiple places.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;M.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 08:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345312#M125314</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-09-10T08:17:09Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345313#M125315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Marcin. ISE supports the return of standard RADIUS attributes such as Framed-IP-Address and Framed-IP-Netmask. There is an enhancement request filed support fetching a static IP attribute from Active Directory and sending to the end client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCud10560" target="_blank"&gt;CSCud10560&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISE: Need support for static IP AD attribute &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;ISE currently does not support fetching static IP attribute from Active Directory to send to a client in an Authorization Result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 14:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345313#M125315</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-09-10T14:33:01Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345314#M125316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;The DNS probe in your Cisco ISE deployment, when enabled, allows the profiler to lookup an endpoint, and get the fully qualified domain name (FQDN) of that endpoint. A DNS lookup tries to determine the endpoint fully qualified domain name. Upon an endpoint detection on your Cisco ISE enabled network, a list of endpoint attributes is collected from the NetFlow, DHCP, DHCP SPAN, HTTP, RADIUS, or SNMP probes. For a DNS lookup, one of the following probes must be started along with the DNS probe: DHCP, DHCP SPAN, HTTP, RADIUS, or SNMP.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;The following list shows the specific endpoint attribute, and the probe that collects the attribute:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The dhcp-requested-address attribute—an attribute collected by the DHCP, and DHCP SPAN probes&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The SourceIP attribute—an attribute collected by the HTTP probe&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The Framed-IP-Address attribute—an attribute collected by the RADIUS probe&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;• &lt;/STRONG&gt;The cdpCacheAddress attribute—an attribute collected by the SNMP probe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;The Cisco ISE implements an ARP cache in the profiling service, so that you can reliably map IP addresses and MAC addresses of endpoints. For the ARP cache to function, you must enable either the DHCP probe or the RADIUS probe. The DHCP and RADIUS probes carry IP addresses and MAC addresses of endpoints in the payload data. The dhcp-requested address attribute in the DHCP probe and the Framed-IP-address attribute in the RADIUS probe carry the IP addresses of endpoints, along with their MAC addresses, which can be mapped and stored in the ARP cache.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 06:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345314#M125316</guid>
      <dc:creator>Muhammad Munir</dc:creator>
      <dc:date>2013-09-12T06:53:39Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345315#M125317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I successfully accomplished this using the method you suggested. Thanks a lot.&lt;/P&gt;&lt;P&gt;I would also like to assign IP address to VPN clients using an address pool in the ISE. There is RADIUS attribute Framed-Pool. However, how does it know which address has been used in the pool? Can this attribute be used this way?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 07:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345315#M125317</guid>
      <dc:creator>y.lo</dc:creator>
      <dc:date>2013-09-12T07:31:12Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345316#M125318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When RADIUS sends pool name ASA will just use that pool, it's up to the ASA to maintain pool's free IP addresses etc.&lt;/P&gt;&lt;P&gt;There is no feedback towards authentication server (ISE or any RADIUS for that matter) in regards to which IP address has been assigned.&lt;/P&gt;&lt;P&gt;If you want to know which addresses were assigned to each user you can still poll via SNMP (if that helps).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have a look at &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13299"&gt;https://supportforums.cisco.com/docs/DOC-13299&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(or you can extarct that info via CLI "show vpn-sessiondb ..." )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 08:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345316#M125318</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-09-12T08:08:49Z</dc:date>
    </item>
    <item>
      <title>Assign static IP address to ASA VPN clients by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345317#M125319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What we really want to achieve is to maintain the IP address pool in ISE, but not in ASA. Is that doable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 08:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345317#M125319</guid>
      <dc:creator>y.lo</dc:creator>
      <dc:date>2013-09-12T08:13:05Z</dc:date>
    </item>
    <item>
      <title>No, ISE does not have a</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345318#M125320</link>
      <description>&lt;P&gt;No, ISE does not have a concept of an ip pool, like a dhcp server or an ASA. Only assigning the name of a local ip pool on the ASA or a static hardcoded ip is possible from ise.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 00:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345318#M125320</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-03-20T00:12:53Z</dc:date>
    </item>
    <item>
      <title>Also, getting the ip from AD</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345319#M125321</link>
      <description>&lt;P&gt;Also, getting the ip from AD is supported if you put the ip address in another field than the regular ip address one (which is some weird formatted form of a string that ise doesnt understand), that is under every user, as long as the field is a string.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 00:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345319#M125321</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-03-20T00:16:34Z</dc:date>
    </item>
    <item>
      <title>Where (as in what part of the</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345320#M125322</link>
      <description>&lt;P&gt;Where (as in what part of the config) can the ip pool name (located on ASA) be assigned in ISE?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 22:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345320#M125322</guid>
      <dc:creator>mburrell5</dc:creator>
      <dc:date>2014-06-02T22:19:39Z</dc:date>
    </item>
    <item>
      <title>Try this and see if it works</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345321#M125323</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Try this and see if it works:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Dictionaries &amp;gt; System &amp;gt; Radius&amp;nbsp;&amp;gt; RADIUS Vendors &amp;gt; Cisco-VPN3000&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Add&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Attribute Name: CVPN3000/ASA/PIX7x-Group-Based-Address-Pools&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Data Type: String&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Direction: Both&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;ID: 217&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;** Do rate helpful posts **&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 22:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345321#M125323</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-06-02T22:32:39Z</dc:date>
    </item>
    <item>
      <title>Thanks, what I really want to</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345322#M125324</link>
      <description>&lt;P&gt;Thanks, what I really want to use is IETF Attribute 88 Framed-Pool but it is not present in the IETF dictionary. My mention of ASA was really just to get the concept across.&lt;/P&gt;&lt;P&gt;I have a Telstra Radius proxy that I need to authenticate remote users with using RADIUS and issue the users IP addresses. At present this works happily using IETF Attribute 88 Framed-Pool authenticating to ACS, but struggling to find support for this on ISE 1.2. I dont think ISE supports RFC2869 (which is what Attribute 88 is part of)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 23:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345322#M125324</guid>
      <dc:creator>mburrell5</dc:creator>
      <dc:date>2014-06-02T23:42:12Z</dc:date>
    </item>
    <item>
      <title>https://supportforums.cisco</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345323#M125325</link>
      <description>&lt;P&gt;https://supportforums.cisco.com/discussion/12220321/ise-12-ietf-attribute-88-framed-pool-not-available&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 05:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345323#M125325</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-06-03T05:54:26Z</dc:date>
    </item>
    <item>
      <title>Hi Marcin,Is there a way of</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345324#M125326</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;Hi Marcin,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;Is there a way of &amp;nbsp;Mapping remote users MAC address to username in LDAP server ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;I have a client who wants to&amp;nbsp;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; background-color: rgb(245, 245, 245);"&gt;restrict VPN access to firewall based on MAC address of the client or end user vpn client access restriction in any way.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; background-color: rgb(245, 245, 245);"&gt;Basically we want to only allow remote users connect with their work laptop and not from their home PC for instance.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Sep 2014 10:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345324#M125326</guid>
      <dc:creator>purva.kate</dc:creator>
      <dc:date>2014-09-13T10:27:22Z</dc:date>
    </item>
    <item>
      <title>Jatin,     Just wanted to let</title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345325#M125327</link>
      <description>&lt;P&gt;Jatin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Just wanted to let you know that I used your suggestion to use ISE 1.4 to assign the proper IP Pool to an Authorization Profile.&amp;nbsp; Worked great.&amp;nbsp; Thank you for posting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 13:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345325#M125327</guid>
      <dc:creator>mleiby</dc:creator>
      <dc:date>2015-07-22T13:24:43Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345326#M125328</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the topology.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Users are connecting via AnyConnect VPN and are getting authorized with ISE and AD. Windows DHCP Server is giving dynamically IP addreses. The customer wants to assign static MAC-IP binding in the DHCP Server so they can use the firewall to filter based on the VPN IP addresses.&lt;/P&gt;
&lt;P&gt;Internet &amp;nbsp;----- ASA ------ LAN --- ISE and Windows DHCP Server.&lt;/P&gt;
&lt;P&gt;Can you provide more information how can I assign MAC-IP binding in a Windows DHCP Server through AnyConnect VPN and ISE.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 21:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/assign-static-ip-address-to-asa-vpn-clients-by-ise/m-p/2345326#M125328</guid>
      <dc:creator>rchockeelopez</dc:creator>
      <dc:date>2017-04-05T21:54:12Z</dc:date>
    </item>
  </channel>
</rss>

