<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - AAA radius authentication for NAD access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003379#M255396</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick replys , and now&amp;nbsp; ok , I've configured the following authorization policy :&lt;/P&gt;&lt;P&gt;Rule Name : Nad Auth&lt;/P&gt;&lt;P&gt;Conditions&lt;/P&gt;&lt;P&gt;if: Any&lt;/P&gt;&lt;P&gt;AND : AD1:ExternalGroups EQUALS IT_Departments&lt;/P&gt;&lt;P&gt;Permissions , then PermitAccess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I don't understand is that it needs to match an "identity group" which can be either "Endpoint Identity group" or "Users Identity group" , I am limited with the if statement and cannot chose the same &lt;SPAN style="text-decoration: underline;"&gt;device group&lt;/SPAN&gt; a choose before .&lt;/P&gt;&lt;P&gt;How can i do that , i am thinking ahead an asking myself if in other cases a user might match this policy rule and can interfer ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2012 14:03:05 GMT</pubDate>
    <dc:creator>vvvnnnzzz</dc:creator>
    <dc:date>2012-07-13T14:03:05Z</dc:date>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003375#M255330</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have configured the switches to use the ISE as the Radius server to authenticate with , on the ISE i've configured an authentication policy&lt;/P&gt;&lt;P&gt;for the "NADs" using the "Wired Devices" group which points to the AD indentity source to authenticate against .&lt;/P&gt;&lt;P&gt;While testing the login access to the switches we've come up with 2 results :&lt;/P&gt;&lt;P&gt;1.A domain user can indeed login to the switch as intended.&lt;/P&gt;&lt;P&gt;2.Every domain user which exists in the AD indentity source can login , this is an undesired result .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am trying to search for a way to restrict access to the NADs to only a particular group belonging to the AD , for example the group/ou&lt;/P&gt;&lt;P&gt;of the IT_department only .&lt;/P&gt;&lt;P&gt;I haven't been successfull , would appreciate any ideas on how to accomplish this .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch configurations :&lt;/P&gt;&lt;P&gt;=================&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; ISE Authentication policy&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;Policy Name : NADs Authentication&lt;/P&gt;&lt;P&gt;Condition:&amp;nbsp; "DEVICE:Device Type Equals :All Device Types#Wired"&lt;/P&gt;&lt;P&gt;Allowed Protocol : Default Network Access&lt;/P&gt;&lt;P&gt;use identity source : AD1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003375#M255330</guid>
      <dc:creator>vvvnnnzzz</dc:creator>
      <dc:date>2019-03-11T02:17:57Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003376#M255340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add another condition to you current authorization policy which looks for the AD:ExternalGroup and set that equal to your OU in AD. Click the plus button in the current policy to add another conidition to this policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 13:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003376#M255340</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-13T13:39:51Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003377#M255355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Your are refering to the authorization policy whereas I do not ( i am talking about the authentication ) , the moment i get the prompt of the switch for username+pass and i am using a correct domain user i will be granted access , the authorization policy doesnt come in effect here , am I wrong ?&lt;/P&gt;&lt;P&gt;At this specific case i am not trying to authorize the user to a specific network vlan or envirounment but to only control the users allowed to admin the switch .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 13:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003377#M255355</guid>
      <dc:creator>vvvnnnzzz</dc:creator>
      <dc:date>2012-07-13T13:48:43Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003378#M255373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct, you can not limit authentication to a specific group of users, only the database they reside in. It is up to the authorization policy then to find what group they are a member of and then give the configured access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 13:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003378#M255373</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-13T13:52:35Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003379#M255396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick replys , and now&amp;nbsp; ok , I've configured the following authorization policy :&lt;/P&gt;&lt;P&gt;Rule Name : Nad Auth&lt;/P&gt;&lt;P&gt;Conditions&lt;/P&gt;&lt;P&gt;if: Any&lt;/P&gt;&lt;P&gt;AND : AD1:ExternalGroups EQUALS IT_Departments&lt;/P&gt;&lt;P&gt;Permissions , then PermitAccess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I don't understand is that it needs to match an "identity group" which can be either "Endpoint Identity group" or "Users Identity group" , I am limited with the if statement and cannot chose the same &lt;SPAN style="text-decoration: underline;"&gt;device group&lt;/SPAN&gt; a choose before .&lt;/P&gt;&lt;P&gt;How can i do that , i am thinking ahead an asking myself if in other cases a user might match this policy rule and can interfer ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 14:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003379#M255396</guid>
      <dc:creator>vvvnnnzzz</dc:creator>
      <dc:date>2012-07-13T14:03:05Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003380#M255432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do not worry about the condition on the left since those are for the internal endpoint and user database. you will use the original policy you pasted but click the &lt;SPAN __jive_emoticon_name="plus" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/plus.gif"&gt;&lt;/SPAN&gt; and combine it with the AD external group so that when both conditions succeed you will then get the result you referenced in the policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 14:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003380#M255432</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-13T14:09:56Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003381#M255460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think i understood your idea , I've added the same group as a condition and combined with the AD:external groups&lt;/P&gt;&lt;P&gt;and that should do the work .&lt;/P&gt;&lt;P&gt;I've attached a screenshot to display the conditions I've set &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/5/7/95757-ise_auth_nad.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;now all that remains is to test it on site &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; , since this is a limited lab envirounment .&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 14:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003381#M255460</guid>
      <dc:creator>vvvnnnzzz</dc:creator>
      <dc:date>2012-07-13T14:17:44Z</dc:date>
    </item>
    <item>
      <title>ISE - AAA radius authentication for NAD access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003382#M255499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem that is how I configure the policies, please remember to rate any helpful feedback after you are finished with your testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 14:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-aaa-radius-authentication-for-nad-access/m-p/2003382#M255499</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-13T14:22:16Z</dc:date>
    </item>
  </channel>
</rss>

