<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where to find MUD generated ACL in ISE ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3871354#M472676</link>
    <description>I was under the impression that the ACL component was a future enhancement for MUD and not something that is currently implemented in ISE 2.6. Today ISE will look up MUD and provide endpoint attributes that are visible in Context Visibility, but that is the current extent of it.</description>
    <pubDate>Wed, 12 Jun 2019 00:19:57 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-06-12T00:19:57Z</dc:date>
    <item>
      <title>Where to find MUD generated ACL in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3870040#M472358</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;I had been playing for a while with &lt;A href="https://developer.cisco.com/docs/mud/#!what-is-mud" target="_self"&gt;MUD,&lt;/A&gt;&amp;nbsp;Cisco do provide a sandbox with ISE in which it get a RADIUS packet with MUD URL and after that it forward it to the MUD manager inside the ISE as shown below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mud-architecture.png" style="width: 654px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/38294iA6402BA8C5FE3CC8/image-dimensions/654x251?v=v2" width="654" height="251" role="button" title="mud-architecture.png" alt="mud-architecture.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the ISE and the MUD Controller/Manager is one thing since it's included in the ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the sandbox there is demo for uploading a LLDP packet with MUD url as shown below, Sandbox can be requested &lt;A href="https://devnetsandbox.cisco.com/RM/Diagram/Index/da3e6951-b95d-46b7-b56f-1941546d6320?diagramType=Topology" target="_self"&gt;from here&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mud-demo.PNG" style="width: 870px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/38295i97335AB7C27C5ECE/image-size/large?v=v2&amp;amp;px=999" role="button" title="mud-demo.PNG" alt="mud-demo.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After that new end point will appear, now i have the following issues&lt;/P&gt;&lt;P&gt;1. ACL should be created from the MUD file, on ISE i was not able to find it anywhere, so where i can found the generated Access Lists ?&lt;/P&gt;&lt;P&gt;2. The Demo and other PCAP files when uploaded get authentication failure on RADIUS&amp;nbsp; as shown below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="auth_fail.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/38297i5B680CF113D72998/image-size/large?v=v2&amp;amp;px=999" role="button" title="auth_fail.PNG" alt="auth_fail.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be glad to get answer for the issues above and how to get one complete flow [on the provided demo files]&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2019 17:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3870040#M472358</guid>
      <dc:creator>darkingdoom</dc:creator>
      <dc:date>2019-06-09T17:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Where to find MUD generated ACL in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3870758#M472370</link>
      <description>&lt;P&gt;The authentication failure is expected as ISE does not have the endpoint in its database but the intention of the demo was&lt;/P&gt;
&lt;P&gt;to provide a general idea of MU.&lt;/P&gt;
&lt;P&gt;For example notice under context visibility that the device is profiled (&lt;SPAN class="td-span"&gt;IOT-MUD-genisyslighting_files_MUD_79590001A4_json&lt;/SPAN&gt;)&lt;/P&gt;
&lt;P&gt;I agree this is limited and not yet fully functional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 07:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3870758#M472370</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-06-12T07:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Where to find MUD generated ACL in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3871070#M472377</link>
      <description>&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;Will keep following, any estimated duration ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3871070#M472377</guid>
      <dc:creator>darkingdoom</dc:creator>
      <dc:date>2019-06-11T15:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where to find MUD generated ACL in ISE ?</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3871354#M472676</link>
      <description>I was under the impression that the ACL component was a future enhancement for MUD and not something that is currently implemented in ISE 2.6. Today ISE will look up MUD and provide endpoint attributes that are visible in Context Visibility, but that is the current extent of it.</description>
      <pubDate>Wed, 12 Jun 2019 00:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-find-mud-generated-acl-in-ise/m-p/3871354#M472676</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-06-12T00:19:57Z</dc:date>
    </item>
  </channel>
</rss>

