<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity rules priority in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625840#M287636</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;It&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;solved the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;problem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Feb 2011 20:20:10 GMT</pubDate>
    <dc:creator>boris.majstorovic</dc:creator>
    <dc:date>2011-02-24T20:20:10Z</dc:date>
    <item>
      <title>Identity rules priority</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625838#M287589</link>
      <description>&lt;P&gt;Our customer want to implement 802.1x autentication with ACS 5.2 and AD as external identiti base.&lt;/P&gt;&lt;P&gt;But when non802.1xcapable device conect to 802.1x enabled switch port autentification should be with MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have configured switch with 802.1x and MAC auth bypass.&lt;/P&gt;&lt;P&gt;Also define AD as external identiti base, and MAC addreses in internal hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two policies in&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Access Policies&lt;/SPAN&gt; &amp;gt; ... &amp;gt; &lt;A class="cuesBreadcrumbLink" href="https://community.cisco.com/" target="_blank"&gt;Access Services&lt;/A&gt; &amp;gt; &lt;A class="cuesBreadcrumbLink" href="https://community.cisco.com/" target="_blank"&gt;Default Network Access&lt;/A&gt; &amp;gt; &lt;SPAN class="cuesBreadcrumbLast"&gt;Identity&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cuesBreadcrumbLast"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cuesBreadcrumbLast"&gt;&lt;CENTER&gt;&lt;/CENTER&gt;&lt;/SPAN&gt;2.&lt;A href="https://community.cisco.com/" target="_blank"&gt;AD&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NDG:Location in All Locations&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD1&lt;/P&gt;&lt;P&gt;1. &lt;A href="https://community.cisco.com/" target="_blank"&gt;Non802.1xCapableDevices&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NDG:Location in All Locations&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internal Hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is taht only frst rule is considered. If we try to autenticate with LapTop with 802.1x disabled (MAC is in internal host) autentication - OK. When we enable 802.1x on LAN there is no autentication (user not found).&lt;/P&gt;&lt;P&gt;After we changed order of policies:&lt;/P&gt;&lt;P&gt;1.&lt;A href="https://community.cisco.com/" target="_blank"&gt;AD&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NDG:Location in All Locations&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD1&lt;/P&gt;&lt;P&gt;2. &lt;A href="https://community.cisco.com/" target="_blank"&gt;Non802.1xCapableDevices&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NDG:Location in All Locations&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internal Hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;situation&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;reversed, user is autenticated but MAC isn't.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Where&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;error?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625838#M287589</guid>
      <dc:creator>boris.majstorovic</dc:creator>
      <dc:date>2019-03-11T00:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity rules priority</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625839#M287619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Access Policies &amp;gt; &amp;gt; Access Services &amp;gt; Default Network Access &amp;gt; Identity, if you use "&amp;nbsp;&amp;nbsp; &lt;LABEL for="rulebased_"&gt;Rule based result selection"&lt;/LABEL&gt;&lt;/P&gt;&lt;P&gt;ACS should just usethe first match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure a "Idnetity Store Sequence" in Users and Identity Stores &amp;gt; Identity Store Sequences, make sure you select the "internal host" first and then AD. Then you can use this "identity store sequence" in "Default Network Access &amp;gt; Identity".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 22:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625839#M287619</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2011-02-15T22:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity rules priority</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625840#M287636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;It&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;solved the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;problem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 20:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-rules-priority/m-p/1625840#M287636</guid>
      <dc:creator>boris.majstorovic</dc:creator>
      <dc:date>2011-02-24T20:20:10Z</dc:date>
    </item>
  </channel>
</rss>

