<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and MAB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987487#M455471</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I want to use MAB on a bunch of devices from the same manufacturer that can;t do 802.1x can I create just a single MAB policy and have all the devices hit that policy or whi I have to enter every actual MAC address for each device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Replies rated&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 20:35:35 GMT</pubDate>
    <dc:creator>angel-moon</dc:creator>
    <dc:date>2019-11-21T20:35:35Z</dc:date>
    <item>
      <title>ISE and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987487#M455471</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I want to use MAB on a bunch of devices from the same manufacturer that can;t do 802.1x can I create just a single MAB policy and have all the devices hit that policy or whi I have to enter every actual MAC address for each device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Replies rated&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 20:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987487#M455471</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2019-11-21T20:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987499#M455476</link>
      <description>&lt;P&gt;As long as the manufacturer has the same OUI (first 6 characters of the MAC address) then you can accomplish it with one policy.&amp;nbsp; Your condition would be Radius:Calling-Station-ID starts with &amp;lt;first 6 characters, example: 00-12-34 or 00:12:34 depending on how your accounting is configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also accomplish it by creating a profiling policy with the same condition or a condition to match the OUI by name (as seen in Context Visibility) then using the condition in your authorization policy Endpoint:EndpointPolicy = &amp;lt;ProfileName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, you could populate an Endpoint Group with all of the MAC addresses manually (or bulk import) if desired.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 20:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987499#M455476</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2019-11-21T20:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987520#M455481</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/294321"&gt;@jj27&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, please note that if pushing authz policy via profiled endpoint groups you will require plus licensing.&amp;nbsp; If licensing is a concern I would recommend leveraging a bulk add via rest api.&amp;nbsp; Check this out:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 21:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-mab/m-p/3987520#M455481</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-11-21T21:17:20Z</dc:date>
    </item>
  </channel>
</rss>

