<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Passive ID - Security Group Tags in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985275#M37395</link>
    <description>&lt;P&gt;I'm looking to replace my CDA with ISE for transparent user auth for our WSA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The thing that I'm seeing is when I want to add users and groups to an access policy, I cannot add AD Groups like I can with the CDA setup. I can only use SGT's. &amp;nbsp;That's fine for wireless users who auth with dot1x because I can add the SGT based on AD group.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For wired users not using dot1x passive ID maps the user to the IP, and If I add the username to the access policy on the WSA it works, however these users don't have a SGT. Is there anyway to add a SGT to an AD group? Or anyway to make a policy on the WSA using an AD group with PassiveID and ISE?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:16:09 GMT</pubDate>
    <dc:creator>michaellperrin</dc:creator>
    <dc:date>2019-03-11T07:16:09Z</dc:date>
    <item>
      <title>Passive ID - Security Group Tags</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985275#M37395</link>
      <description>&lt;P&gt;I'm looking to replace my CDA with ISE for transparent user auth for our WSA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The thing that I'm seeing is when I want to add users and groups to an access policy, I cannot add AD Groups like I can with the CDA setup. I can only use SGT's. &amp;nbsp;That's fine for wireless users who auth with dot1x because I can add the SGT based on AD group.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For wired users not using dot1x passive ID maps the user to the IP, and If I add the username to the access policy on the WSA it works, however these users don't have a SGT. Is there anyway to add a SGT to an AD group? Or anyway to make a policy on the WSA using an AD group with PassiveID and ISE?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985275#M37395</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2019-03-11T07:16:09Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985276#M37398</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have same problem, you solved this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 14:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985276#M37398</guid>
      <dc:creator />
      <dc:date>2017-07-19T14:22:27Z</dc:date>
    </item>
    <item>
      <title>I heard it's coming to WSA,</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985277#M37399</link>
      <description>&lt;P&gt;I heard it's coming to WSA, but not yet supported.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 14:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-id-security-group-tags/m-p/2985277#M37399</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2017-07-19T14:49:43Z</dc:date>
    </item>
  </channel>
</rss>

