<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Auth policy based on MAC OUI and SSID in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905251#M226649</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) I have never seen the actual SSID name anywhere in the radius attributes coming from the controller, i always use airespace-wlan-id, and if you wan't to avoid creating multiple rules, make the id's the same on all controllers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Well OUI is part of the mac, so you could maybe use RegEX to filter out specific OUI's. Another way, if you have advanced license, would be to use Profiling, then ISE would do all the hard work of classifying what device is attempting to connect, and you could use that in your authoriz. policy ex . "Profiled:Iphone"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Apr 2012 20:21:55 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2012-04-24T20:21:55Z</dc:date>
    <item>
      <title>ISE Auth policy based on MAC OUI and SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905249#M226558</link>
      <description>&lt;P&gt;I was blocking certain consumer mobile devices from my production WLAN on ACS using this process -&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807669af.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807669af.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The MAC OUI is referenced in the CLI field of the NAR, and the SSID is in the DNIS field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know how to do this on ISE?&amp;nbsp; Two questions -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I can match based on WLAN-ID, but not SSID.&amp;nbsp; My WLAN-IDs for the same SSID don't match between controllers.&amp;nbsp; Do I need to change this and make sure all WLAN-IDs map to the same SSID on each controller?&amp;nbsp; Or, is there a different attribute I can use that refers to the SSID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) What attribute do you use in ISE Authorization conditions to match OUI?&amp;nbsp; And can I match a list of OUIs?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905249#M226558</guid>
      <dc:creator>kevin_miller</dc:creator>
      <dc:date>2019-03-11T02:00:43Z</dc:date>
    </item>
    <item>
      <title>ISE Auth policy based on MAC OUI and SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905250#M226606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for opening a TAC case, basically a bug was filed to fix the logging to show the correct calling station id, currently the ISE reports show the (:) as the delimeter the pcap shows a hyphen. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the bug to track this issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtz41262"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtz41262&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 03:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905250#M226606</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-04-24T03:36:56Z</dc:date>
    </item>
    <item>
      <title>ISE Auth policy based on MAC OUI and SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905251#M226649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) I have never seen the actual SSID name anywhere in the radius attributes coming from the controller, i always use airespace-wlan-id, and if you wan't to avoid creating multiple rules, make the id's the same on all controllers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Well OUI is part of the mac, so you could maybe use RegEX to filter out specific OUI's. Another way, if you have advanced license, would be to use Profiling, then ISE would do all the hard work of classifying what device is attempting to connect, and you could use that in your authoriz. policy ex . "Profiled:Iphone"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 20:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905251#M226649</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-04-24T20:21:55Z</dc:date>
    </item>
    <item>
      <title>ISE Auth policy based on MAC OUI and SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905252#M226677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All.&amp;nbsp; Thanks for the replys.&lt;/P&gt;&lt;P&gt;I was able to do this -&lt;/P&gt;&lt;P&gt;Radius:Called-Station-ID MATCHES .*(SSID)$&lt;/P&gt;&lt;P&gt;Radius:Calling-Station-ID STARTS_WITH 1C-AB-A7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first does match the SSID properly - so I don't need to worry about matching WLAN IDs between controllers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 12:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905252#M226677</guid>
      <dc:creator>kevin_miller</dc:creator>
      <dc:date>2012-04-25T12:23:15Z</dc:date>
    </item>
    <item>
      <title>ISE Auth policy based on MAC OUI and SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905253#M226708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great info, i never noticed the ssid name in the calling station id, maybe it's a new thing in the controller software ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 17:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-policy-based-on-mac-oui-and-ssid/m-p/1905253#M226708</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-04-25T17:03:59Z</dc:date>
    </item>
  </channel>
</rss>

