<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE profiling - match on endpoint FQDN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217878#M183057</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Ends with" does not appear to be an operator.&amp;nbsp; My choices are EQUALS, NOTEQUALS, GREATERTHAN, LESSTHAN or CONTAINS.&amp;nbsp; I will most likely need to use the EQUALS operator to match on my regular expression, but can't figure out what the proper syntax is to match on first few characters and domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 May 2013 21:32:50 GMT</pubDate>
    <dc:creator>Brian Schultz</dc:creator>
    <dc:date>2013-05-03T21:32:50Z</dc:date>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217876#M182958</link>
      <description>&lt;P&gt;I'm trying to come up with a profiling condition to match on FQDN.&amp;nbsp; In this particular example, all corporate workstations have the following common FQDN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abcd-machinename.xyz.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to match on everything except the machinename which can be a wildcard.&amp;nbsp; The profiling condition I've attempted to configure is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP:FQDN CONTAINS ^(abcd)*(\.xyz\.com)$&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never get any matches on this or any variation that I've tried.&amp;nbsp; When I look at the Endpoint in Identity, I do see the full FQDN as an attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help me with the correct syntax to match a FQDN in this manner?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217876#M182958</guid>
      <dc:creator>Brian Schultz</dc:creator>
      <dc:date>2019-03-11T03:23:34Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217877#M183007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you should use "Ends with" operator against the domain name "xyz.com" instead of using "contains" operator against entire FQDN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more detail, the following link may be helpful:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Creating a New Authorization Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_authz_polprfls.html#wp1082656"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_authz_polprfls.html#wp1082656&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above link, review the Note:&lt;STRONG&gt;The "Matches" operator supports and uses regular expressions (REGEX) not wildcards.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my understanding, regular expressions can't be used against all operators&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 21:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217877#M183007</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-03T21:22:51Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217878#M183057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Ends with" does not appear to be an operator.&amp;nbsp; My choices are EQUALS, NOTEQUALS, GREATERTHAN, LESSTHAN or CONTAINS.&amp;nbsp; I will most likely need to use the EQUALS operator to match on my regular expression, but can't figure out what the proper syntax is to match on first few characters and domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 21:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217878#M183057</guid>
      <dc:creator>Brian Schultz</dc:creator>
      <dc:date>2013-05-03T21:32:50Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217879#M183074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regardless of&amp;nbsp; &lt;STRONG&gt;Ends With&lt;/STRONG&gt; operator, your filter may focus on the domain name xyz.com instead of entire FQDN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regular expressions pattern varies among different platforms. Writing perfect and precise regex is a tricky method that can't be discussed at forum.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But the best way out is you try these online editors:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://gskinner.com/RegExr/"&gt;http://gskinner.com/RegExr/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://myregexp.com/"&gt;http://myregexp.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.regexplanet.com/"&gt;http://www.regexplanet.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may also search for &lt;STRONG&gt;Regular Expressions Editor / Tester&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 23:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217879#M183074</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-03T23:43:07Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217880#M183113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Brian,&lt;/P&gt;&lt;P&gt;Upcoming ISE 1.2 which is to be released soon, has the additional operators "Starts With" &amp;amp; "Ends With" operators that will be useful,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For DHCP host-name you can use Starts With&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;For domain name Ends With&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 15:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217880#M183113</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-17T15:59:59Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217881#M183152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Ashok.&amp;nbsp; Until 1.2 gets released, we will use the CONTAINS operator as we discussed over the phone earlier this week.&amp;nbsp; Thanks for your assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 16:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217881#M183152</guid>
      <dc:creator>Brian Schultz</dc:creator>
      <dc:date>2013-05-17T16:20:15Z</dc:date>
    </item>
    <item>
      <title>ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217882#M183196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to add what all you discussed so far;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A new defect has bee filed on the same topic&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCug82199" target="_blank"&gt;CSCug82199&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Profiler Conditions Using REGEX as Attribute Value Don't Work Correctly &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Symptom:&lt;/B&gt; Profiling condition does not match a REGEX configured in the Attribute Value text box when set to EQUAL the contents&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Conditions:&lt;/B&gt; REGEX configured with a wildcard portion in the middle fail the be profiled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Workaround:&lt;/B&gt; Use a simple text value in the Attribute Value Box matched with the CONTAINS operator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 19:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217882#M183196</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-17T19:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - match on endpoint FQDN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217883#M183239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jatin,&lt;/P&gt;&lt;P&gt;At the time of writing this message, the bug detail page is not accessible. Please confirm the URL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I wanted to share my views on the operators' use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although, ISE does not seem to be functioning in this way but logically EQUALS, GREATER THAN, LESS THAN operators (should) call for mathematical evaluation of the expression, whereas the textual operation, comparison, analysis etc. would require the following operators:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MATCHES&lt;/P&gt;&lt;P&gt;STARTS WITH&lt;/P&gt;&lt;P&gt;ENDS WITH&lt;/P&gt;&lt;P&gt;CONTAINS&lt;/P&gt;&lt;P&gt;DOESNT CONTAIN&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also noticed that in earlier ISE versions, FQDN was displayed in hex form with 4 hex digits (3 leading zeros) followed by FQDN name. I shall try to check the raw FQDN value returned in AV pairs. This may be the reason of failure of EQUALS operator&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 May 2013 06:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-match-on-endpoint-fqdn/m-p/2217883#M183239</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-18T06:20:46Z</dc:date>
    </item>
  </channel>
</rss>

