<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE - Authenticate WIFI Devices Using MAB, Block All Others in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authenticate-wifi-devices-using-mab-block-all-others/m-p/3949022#M456170</link>
    <description>&lt;P&gt;I am trying to setup WIFI authenticating MAB devices via Cisco ISE.&lt;/P&gt;&lt;P&gt;The authentication comes through to Cisco ISE and the devices connect but I am getting other devices as well.&lt;/P&gt;&lt;P&gt;I want to restrict authentication to my list of devices only and block all others.&lt;/P&gt;&lt;P&gt;All I can seem to point to for a list of devices is Internal Endpoints, which just seems to be everything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to attached for the authentication policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running ISE 2.2.0.470&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2019 08:37:24 GMT</pubDate>
    <dc:creator>cheery Tomato</dc:creator>
    <dc:date>2019-10-28T08:37:24Z</dc:date>
    <item>
      <title>Cisco ISE - Authenticate WIFI Devices Using MAB, Block All Others</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authenticate-wifi-devices-using-mab-block-all-others/m-p/3949022#M456170</link>
      <description>&lt;P&gt;I am trying to setup WIFI authenticating MAB devices via Cisco ISE.&lt;/P&gt;&lt;P&gt;The authentication comes through to Cisco ISE and the devices connect but I am getting other devices as well.&lt;/P&gt;&lt;P&gt;I want to restrict authentication to my list of devices only and block all others.&lt;/P&gt;&lt;P&gt;All I can seem to point to for a list of devices is Internal Endpoints, which just seems to be everything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to attached for the authentication policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running ISE 2.2.0.470&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 08:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authenticate-wifi-devices-using-mab-block-all-others/m-p/3949022#M456170</guid>
      <dc:creator>cheery Tomato</dc:creator>
      <dc:date>2019-10-28T08:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Authenticate WIFI Devices Using MAB, Block All Others</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authenticate-wifi-devices-using-mab-block-all-others/m-p/3949449#M456172</link>
      <description>The pictures you provided are of your Authentication Policy. MAB will essentially authenticate anything within your Internal Endpoint database. You'll need to add all of the mac addresses of the devices you want to connect to this SSID into some sort of endpoint group. Then call that group out in your Authorization policy as permit then deny everything else.&lt;BR /&gt;&lt;BR /&gt;Of course, as with all mab authentications you open yourself up to mac spoofing. So be wary of the implications of that.</description>
      <pubDate>Mon, 28 Oct 2019 19:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authenticate-wifi-devices-using-mab-block-all-others/m-p/3949449#M456172</guid>
      <dc:creator>CarlCarlson1234</dc:creator>
      <dc:date>2019-10-28T19:59:34Z</dc:date>
    </item>
  </channel>
</rss>

