<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.1 Authorization Policy matching Identity Groups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473383#M387416</link>
    <description>&lt;P&gt;Hi Has anyone managed to get an Auth Policy within an Access Service to match devices based on Identity Group Membership?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Auth Rule looks like this but doesn't ever got hit???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/4/1/4145-Auth%20rule.JPG" alt="Auth rule.JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:08:16 GMT</pubDate>
    <dc:creator>rhodrijenkins</dc:creator>
    <dc:date>2019-03-11T00:08:16Z</dc:date>
    <item>
      <title>ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473383#M387416</link>
      <description>&lt;P&gt;Hi Has anyone managed to get an Auth Policy within an Access Service to match devices based on Identity Group Membership?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Auth Rule looks like this but doesn't ever got hit???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/4/1/4145-Auth%20rule.JPG" alt="Auth rule.JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473383#M387416</guid>
      <dc:creator>rhodrijenkins</dc:creator>
      <dc:date>2019-03-11T00:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473384#M387452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;When you say devices based on identity group membership, do you mean external groups because I could see that you have selected AD in your compound condition. Looks like you have added this attribute inside the Active directory &amp;gt; directory attributes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If this is for ACS internal groups then we may try some more stuff&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 22:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473384#M387452</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-05-14T22:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473385#M387522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JK,&lt;/P&gt;&lt;P&gt;This is using internal groups. The compound condition I'm using matches &lt;STRONG&gt;System:IdentityGroup in All Groups:IPPhones&lt;/STRONG&gt;. Then the phone in question is a member of the ID group IPPhones. I've also tried setting the compound condition to &lt;STRONG&gt;Internal Users:UserIdentityGroup in All Groups:IPPhones&lt;/STRONG&gt; but still to no avail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rhodri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 08:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473385#M387522</guid>
      <dc:creator>rhodrijenkins</dc:creator>
      <dc:date>2010-05-17T08:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473386#M387575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets try this way. VPN is an internal group and firewall is an device here.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/6/1/4165-auth_pol.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 12:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473386#M387575</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-05-17T12:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473387#M387630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have almost the exact same matching policy and it works fine.&lt;/P&gt;&lt;P&gt;Does your authentication pass successfully? What does the AAA report tell you? Maybe it hits other rules first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tao&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 19:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473387#M387630</guid>
      <dc:creator>jintao99</dc:creator>
      <dc:date>2010-05-17T19:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authorization Policy matching Identity Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473388#M387697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmm all very strange. I configured this on an Eval copy of ACS. This morning the real box arrived so once installed I'll try this again and report the results back here.&lt;/P&gt;&lt;P&gt;Thanks gentlemen for your assistance&lt;/P&gt;&lt;P&gt;Rhodri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 14:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authorization-policy-matching-identity-groups/m-p/1473388#M387697</guid>
      <dc:creator>rhodrijenkins</dc:creator>
      <dc:date>2010-05-18T14:40:54Z</dc:date>
    </item>
  </channel>
</rss>

