<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did you select the group in in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854181#M36413</link>
    <description>&lt;P&gt;Did you select the group in the first column right after the word "if" ? or have you put it in the conditions column after the word "and" ? It needs to be selected in the first one. Using conditions to match AD groups does not work.&lt;/P&gt;
&lt;P&gt;It would help if you uploaded a screenshot of the rules.&lt;/P&gt;</description>
    <pubDate>Sun, 01 May 2016 11:37:05 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2016-05-01T11:37:05Z</dc:date>
    <item>
      <title>only specific groups should get authenticated on ISE instead of entire AD</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854176#M36406</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;
&lt;P&gt;I &amp;nbsp;integrated ISE to AD, but all users in AD are getting authenticated against my&amp;nbsp;network&amp;nbsp;devices and get landed in exec mode, though these users&amp;nbsp;do not have privileges to do the configuration, only network admins are able to do so becoz i have defined admin&amp;nbsp;groups names in authorization policy, now what i want to define only specific groups names in authentication policy instead of AD name, , is there any way to do so ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards/Tash&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854176#M36406</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2019-03-11T06:43:27Z</dc:date>
    </item>
    <item>
      <title>You should just use more</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854177#M36408</link>
      <description>&lt;P&gt;You should just use more specific authorization rules for admins and then deny all others access, theres no need to create specific authentication rules.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2016 20:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854177#M36408</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-04-30T20:17:30Z</dc:date>
    </item>
    <item>
      <title>Create a condition in the</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854178#M36409</link>
      <description>&lt;P&gt;Create a condition in the authorization rule&amp;nbsp;that requires the External Groups for the AD to contain the Network&amp;nbsp;Admins domain group (whatever it is called). If you have multiple groups, use the OR operator to have multiple external groups defined.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2016 22:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854178#M36409</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-04-30T22:06:18Z</dc:date>
    </item>
    <item>
      <title>Hi Joseph,</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854179#M36410</link>
      <description>&lt;P&gt;Hi Joseph,&lt;/P&gt;
&lt;P&gt;Thanks for your reply&lt;/P&gt;
&lt;P&gt;I created below rules in authorization policy,&lt;/P&gt;
&lt;P&gt;Rule-name -any- AD-External groups equals to (Network admin groups)&lt;/P&gt;
&lt;P&gt;deny-rule if no-match denyall. but users are still get authenticated for level 0&lt;/P&gt;
&lt;P&gt;Please let me know if i am doing it correctly.&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Tash&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 05:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854179#M36410</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2016-05-01T05:01:30Z</dc:date>
    </item>
    <item>
      <title>Hello Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854180#M36411</link>
      <description>&lt;P&gt;Hello Jan,&lt;/P&gt;
&lt;P&gt;Thanks for the reply,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But that is what i did,&lt;/P&gt;
&lt;P&gt;I created below rules in authorization policy,&lt;/P&gt;
&lt;P&gt;Rule-name -any- AD-External groups equals to (Network admin groups)&lt;/P&gt;
&lt;P&gt;deny-rule if no-match denyall. but users are still get authenticated for level 0&lt;/P&gt;
&lt;P&gt;Please let me know if i am doing it correctly&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Tash&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 05:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854180#M36411</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2016-05-01T05:02:36Z</dc:date>
    </item>
    <item>
      <title>Did you select the group in</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854181#M36413</link>
      <description>&lt;P&gt;Did you select the group in the first column right after the word "if" ? or have you put it in the conditions column after the word "and" ? It needs to be selected in the first one. Using conditions to match AD groups does not work.&lt;/P&gt;
&lt;P&gt;It would help if you uploaded a screenshot of the rules.&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 11:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854181#M36413</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-01T11:37:05Z</dc:date>
    </item>
    <item>
      <title>That should work. You may</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854182#M36415</link>
      <description>&lt;P&gt;That should work. It depends on any rules you have before that one that could hit first. Check your authentication logs after someone attempts to log in to make sure it is working.&lt;/P&gt;
&lt;P&gt;You may have to change the Equals to Contains. I've had issues with nested groups and the equals not hitting.&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 13:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854182#M36415</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-05-01T13:24:21Z</dc:date>
    </item>
    <item>
      <title>Hi Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854183#M36416</link>
      <description>&lt;P&gt;Hi Jan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have chosen "any" right after "if" becoz i could not find groups that i have retrieved from AD&lt;/P&gt;
&lt;P&gt;After "any " "and "I have selected &amp;nbsp;AD-External groups equals to admingroup.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please find the screenshot.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Tash&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 16:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854183#M36416</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2016-05-01T16:49:22Z</dc:date>
    </item>
    <item>
      <title>That won't work, did you add</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854184#M36417</link>
      <description>&lt;P&gt;That won't work, did you add the groups you wan't to check for membership of in the menu External Identity Sources/Active Directory/AD-name/Groups? The ones you add there, should show up when you press the + next to "if" and select the name you gave your external ad definition.&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2016 18:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854184#M36417</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-01T18:29:51Z</dc:date>
    </item>
    <item>
      <title>Hi Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854185#M36418</link>
      <description>&lt;P&gt;Hi Jan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I need to check that becoz next to if i can see only AD- External groups and on the last tab i could find AD groups.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Tash&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 09:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854185#M36418</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2016-05-02T09:22:10Z</dc:date>
    </item>
    <item>
      <title>Actually, i was wrong the</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854186#M36419</link>
      <description>&lt;P&gt;Actually, i was wrong the identity groups you select in the column after the "if" is only internal ise identity groups, it should be chosen in the regular conditions as AD:Externalgroups="the group you added to your AD settings", that group should be listed.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 13:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854186#M36419</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-02T13:20:41Z</dc:date>
    </item>
    <item>
      <title>Hi jan</title>
      <link>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854187#M36420</link>
      <description>&lt;P&gt;Hi jan&lt;/P&gt;
&lt;P&gt;Yes..that is how i created these conditions..&lt;/P&gt;
&lt;P&gt;Admin if any AD-External-group equals networkadmingroup.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Tabish&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 13:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/only-specific-groups-should-get-authenticated-on-ise-instead-of/m-p/2854187#M36420</guid>
      <dc:creator>tabish bhat</dc:creator>
      <dc:date>2016-05-02T13:41:10Z</dc:date>
    </item>
  </channel>
</rss>

