<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can choose a new identity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082209#M25797</link>
    <description>&lt;P&gt;You can choose a new identity store for the Authentication policy you are hitting. All ID stores should show up as options to choose in a dropdown See picture attached.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2017 15:28:29 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2017-07-12T15:28:29Z</dc:date>
    <item>
      <title>DenyAccess Identity Store on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082208#M25796</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've Cisco ISE 2.2.0.470 patch 1.&lt;/P&gt;
&lt;P&gt;Every time that a user tries to access the network via MAB Authentication, authentication fails.&lt;/P&gt;
&lt;P&gt;Failure reason is "22017 Selected Identity Source is DenyAccess".&lt;/P&gt;
&lt;P&gt;The resolution is Select a different identity source.&lt;/P&gt;
&lt;P&gt;The identity store is in fact DenyAccess while previously the identity store of my users was Guest_Users.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How could I select a different identity store?&lt;/P&gt;
&lt;P&gt;How could I change DenyAccess identity store?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Antonio&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082208#M25796</guid>
      <dc:creator>antonio.dinapoli</dc:creator>
      <dc:date>2019-03-11T07:50:56Z</dc:date>
    </item>
    <item>
      <title>You can choose a new identity</title>
      <link>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082209#M25797</link>
      <description>&lt;P&gt;You can choose a new identity store for the Authentication policy you are hitting. All ID stores should show up as options to choose in a dropdown See picture attached.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 15:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082209#M25797</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-07-12T15:28:29Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082210#M25798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;thanks for your reply.&lt;/P&gt;
&lt;P&gt;It doesn't work or maybe I've configured the authentication policy in a wrong manner.&lt;/P&gt;
&lt;P&gt;Actual authentication policies are shown in the picture attached.&lt;/P&gt;
&lt;P&gt;Yesterday there wasn't the MAB_SG_copy1.&lt;/P&gt;
&lt;P&gt;Yesterday users hit the MAB_SG policy and it was right in my scenario.&lt;/P&gt;
&lt;P&gt;The error messages were:&lt;/P&gt;
&lt;P&gt;Failure reason is "22017 Selected Identity Source is DenyAccess".&lt;/P&gt;
&lt;P&gt;The resolution is Select a different identity source.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;After your reply&amp;nbsp;I've configured also the MAB_SG_copy1 policy.&lt;/P&gt;
&lt;P&gt;This policy is&amp;nbsp;very similar to&amp;nbsp;the MAB_SG policy with the&amp;nbsp;difference of Identity Store that is DenyAccess store instead of All_user_ID_store.&lt;/P&gt;
&lt;P&gt;I use&amp;nbsp;DenyAccess identity store to try to permit access to "Denyaccess" users.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Identity Source Details are the same for both the policies.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Now users hit that policy but the failure messages are the same of the MAB_SG policy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is this configuration correct? Did you mean this type of configuration?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The strange fact is that MAB_SG policy worked well for some days and suddenly, after I've reloaded my ISE, it began to deny access to my users.&lt;/P&gt;
&lt;P&gt;I've reloaded my ISE because I've upgraded&amp;nbsp;cpu and ram (not disk).&lt;/P&gt;
&lt;P&gt;I don't know if the resource upgrade could have influenced the authentication behaviour.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Antonio&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 13:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denyaccess-identity-store-on-ise/m-p/3082210#M25798</guid>
      <dc:creator>antonio.dinapoli</dc:creator>
      <dc:date>2017-07-13T13:31:44Z</dc:date>
    </item>
  </channel>
</rss>

