<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 allow only specified client cert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782669#M228743</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not use a single SSID and use dynamic vlan assignments to allow only certain clients to go to certain wlans?  You can use the end station filters as a Mac list and set up a policy to restrict them to certain wlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Sep 2011 05:02:28 GMT</pubDate>
    <dc:creator>ewood2624</dc:creator>
    <dc:date>2011-09-22T05:02:28Z</dc:date>
    <item>
      <title>ACS 5.2 allow only specified client cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782666#M228638</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to implement a policy, where I specify which client cert (CN name) is allowed. Let's say we have 2 SSID's and 2 different client certs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- client1.domain.com should only be allowed to connect to SSID1&lt;/P&gt;&lt;P&gt;- client2.domain.com should only be allowed do connect to SSID2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both SSID's use machine certs for EAP-TLS and both certs are issued by the same CA cert. Does anybody know how to specify this in ACS 5.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782666#M228638</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2019-03-11T01:25:22Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 allow only specified client cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782667#M228687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should be possible &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make conditions based on the CN name as follows:&lt;/P&gt;&lt;P&gt;- Create a custom conditon. Policy Elements &amp;gt; Session Conditions &amp;gt; Custom. Select "Certificate Dictionary" and attribute "Common Name". Give it a name. Once you do this you can create a condition based on this in policies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a RADIUS attribute to extract the SSID? Is it in the "“Called-Station-ID" field&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create authorization policy:&lt;/P&gt;&lt;P&gt;- If "Common Name" equals "client1.domain.com"&amp;nbsp; and "SSID" equals SSID1&amp;nbsp; then "Allow Access"&lt;/P&gt;&lt;P&gt;- If "Common Name" equals "client1.domain.com"&amp;nbsp; and "SSID" equals "Any"&amp;nbsp; then "Deny Access"&lt;/P&gt;&lt;P&gt;- If "Common Name" equals "client2.domain.com"&amp;nbsp; and "SSID" equals SSID2&amp;nbsp; then "Allow Access"&lt;/P&gt;&lt;P&gt;- If "Common Name" equals "client2.domain.com"&amp;nbsp; and "SSID" equals "Any"&amp;nbsp; then "Deny Access"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 16:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782667#M228687</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-09-21T16:20:21Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 allow only specified client cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782668#M228716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jrabinow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for your very quick response - I will try this next week when I am onsite again and will update this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I extract the SSID with a "end station filter" (link to the thread where I got the information from: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3231646#3231646"&gt;https://supportforums.cisco.com/message/3231646&lt;/A&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 16:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782668#M228716</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2011-09-21T16:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 allow only specified client cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782669#M228743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not use a single SSID and use dynamic vlan assignments to allow only certain clients to go to certain wlans?  You can use the end station filters as a Mac list and set up a policy to restrict them to certain wlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 05:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-allow-only-specified-client-cert/m-p/1782669#M228743</guid>
      <dc:creator>ewood2624</dc:creator>
      <dc:date>2011-09-22T05:02:28Z</dc:date>
    </item>
  </channel>
</rss>

