<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Selecting wrong authorization profile in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-authorization-profile/m-p/1844962#M227029</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing ISE in a wired environment.&lt;/P&gt;&lt;P&gt;We have set up two authorization profiles called AD_Machine and AD_User as recommned in Trustsec 2.0 doc.&amp;nbsp; The AD_Machine policy has a condition set on it to look at the AD External Group AD Machines, likewise the AD_User has a condition to look at AD External Group AD Users.&amp;nbsp; At the end of the authorization policy list we have the default policy, this is set to WEBAUTH authorization profile.&lt;/P&gt;&lt;P&gt;What we see is machine auth is granted by the WEBAUTH policy as this is catch all.&amp;nbsp; If I disable WEBAUTH it picks AD_Machine, also if I enable WEBAUTH and remove the AD External Group AD Machines condition it also selects the correct policy.&lt;/P&gt;&lt;P&gt;There seems to be some kind of timing issue when authorizing against an external DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:48:46 GMT</pubDate>
    <dc:creator>g-hopkinson</dc:creator>
    <dc:date>2019-03-11T01:48:46Z</dc:date>
    <item>
      <title>ISE Selecting wrong authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-authorization-profile/m-p/1844962#M227029</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing ISE in a wired environment.&lt;/P&gt;&lt;P&gt;We have set up two authorization profiles called AD_Machine and AD_User as recommned in Trustsec 2.0 doc.&amp;nbsp; The AD_Machine policy has a condition set on it to look at the AD External Group AD Machines, likewise the AD_User has a condition to look at AD External Group AD Users.&amp;nbsp; At the end of the authorization policy list we have the default policy, this is set to WEBAUTH authorization profile.&lt;/P&gt;&lt;P&gt;What we see is machine auth is granted by the WEBAUTH policy as this is catch all.&amp;nbsp; If I disable WEBAUTH it picks AD_Machine, also if I enable WEBAUTH and remove the AD External Group AD Machines condition it also selects the correct policy.&lt;/P&gt;&lt;P&gt;There seems to be some kind of timing issue when authorizing against an external DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-authorization-profile/m-p/1844962#M227029</guid>
      <dc:creator>g-hopkinson</dc:creator>
      <dc:date>2019-03-11T01:48:46Z</dc:date>
    </item>
  </channel>
</rss>

