<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HQ and Remote Wired Guest VLAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024966#M178445</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having trouble to create a standard condition for Policy Authorization.&amp;nbsp; Basically there are HQ and remote locations configure for guest access.&lt;/P&gt;&lt;P&gt;Each location has its own guest vlan.&amp;nbsp; On ISE the standard rule are:&lt;/P&gt;&lt;P&gt;Standard Rule 1 if Unknown AND Wired_MAB then Guest_Access &lt;/P&gt;&lt;P&gt;This rule is working good for HQ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Standard Rule 2 if (Unknown OR MTL_Devices) AND Wired_MAB_MTL_Guest then Montreal_Guest &lt;/P&gt;&lt;P&gt;This rule is design for remote but Standard rule 1 is taking over because first match applied and since the OR condition may cause some problem&lt;/P&gt;&lt;P&gt;with internal users since the condition is Unknown OR MTL_Devices.&amp;nbsp; There is no AND condition for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if anyone has idea or have solved this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:40:08 GMT</pubDate>
    <dc:creator>ttran</dc:creator>
    <dc:date>2019-03-11T02:40:08Z</dc:date>
    <item>
      <title>HQ and Remote Wired Guest VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024966#M178445</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having trouble to create a standard condition for Policy Authorization.&amp;nbsp; Basically there are HQ and remote locations configure for guest access.&lt;/P&gt;&lt;P&gt;Each location has its own guest vlan.&amp;nbsp; On ISE the standard rule are:&lt;/P&gt;&lt;P&gt;Standard Rule 1 if Unknown AND Wired_MAB then Guest_Access &lt;/P&gt;&lt;P&gt;This rule is working good for HQ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Standard Rule 2 if (Unknown OR MTL_Devices) AND Wired_MAB_MTL_Guest then Montreal_Guest &lt;/P&gt;&lt;P&gt;This rule is design for remote but Standard rule 1 is taking over because first match applied and since the OR condition may cause some problem&lt;/P&gt;&lt;P&gt;with internal users since the condition is Unknown OR MTL_Devices.&amp;nbsp; There is no AND condition for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if anyone has idea or have solved this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024966#M178445</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2019-03-11T02:40:08Z</dc:date>
    </item>
    <item>
      <title>HQ and Remote Wired Guest VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024967#M178461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to change the order of your rules, ISE uses the first matched rule from top to bottom, in your case the MTRL is matching the first rule since it is more open than the rule below which has the check for the network device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please change the order and see if this fixes your issue, if this doesnt work, post a screenshot of your policies just to make sure we are on the same page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 15:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024967#M178461</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-12T15:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: HQ and Remote Wired Guest VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024968#M178482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for relying.&amp;nbsp; I tried different way and still no good.&amp;nbsp; Here is the screen shot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 20:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hq-and-remote-wired-guest-vlan/m-p/2024968#M178482</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2012-10-12T20:07:35Z</dc:date>
    </item>
  </channel>
</rss>

