<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803626#M485054</link>
    <description>&lt;P&gt;Trying to understand and apply policy set on ISE 2.4 on the lab environment. Your&amp;nbsp;comments and advice on ISE policy that I just built are appropriated.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy set name&lt;/STRONG&gt; is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Use the allowed protocols that are in Default Network Access&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy set name.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30296iD9FCA71E6E613BFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy set name.jpg" alt="Policy set name.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;AUTH_C Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;AUTH_C Policy name is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Use internal users and if it fails continue to default.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AUTH_C Policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30297i73A8100E08BFE4FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="AUTH_C Policy.jpg" alt="AUTH_C Policy.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;AUTH_Z Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;AUTH_Z Policy name is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Result : Permit access to Karim_lab-switch.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AUTH_Z Policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30298i8F878B17517211CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="AUTH_Z Policy.jpg" alt="AUTH_Z Policy.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Sun, 17 Feb 2019 17:36:16 GMT</pubDate>
    <dc:creator>BigK</dc:creator>
    <dc:date>2019-02-17T17:36:16Z</dc:date>
    <item>
      <title>ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803626#M485054</link>
      <description>&lt;P&gt;Trying to understand and apply policy set on ISE 2.4 on the lab environment. Your&amp;nbsp;comments and advice on ISE policy that I just built are appropriated.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy set name&lt;/STRONG&gt; is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Use the allowed protocols that are in Default Network Access&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy set name.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30296iD9FCA71E6E613BFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy set name.jpg" alt="Policy set name.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;AUTH_C Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;AUTH_C Policy name is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Use internal users and if it fails continue to default.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AUTH_C Policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30297i73A8100E08BFE4FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="AUTH_C Policy.jpg" alt="AUTH_C Policy.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;AUTH_Z Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;AUTH_Z Policy name is self-explanatory&lt;/LI&gt;
&lt;LI&gt;Conditions: Device must be Wired_802.1x &lt;EM&gt;or&lt;/EM&gt; Wired_MAB and be connected to Karim_lab-switch.&lt;/LI&gt;
&lt;LI&gt;Result : Permit access to Karim_lab-switch.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AUTH_Z Policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30298i8F878B17517211CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="AUTH_Z Policy.jpg" alt="AUTH_Z Policy.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 17 Feb 2019 17:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803626#M485054</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-02-17T17:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803749#M485056</link>
      <description>&lt;P&gt;You are using AND operation in your configuration which wrong and should be OR. Also, you can't have two authorization profiles as result in one rule&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 08:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803749#M485056</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-18T08:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803811#M485060</link>
      <description>Based on your screenshot a device needs to be authenticated with bot dot1x AND mab. Your permit access authorization policies will conflict your karim_lab_switch authorization policy.  What is you are trying to do? Device admin? or dot1x for a network device?</description>
      <pubDate>Mon, 18 Feb 2019 06:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803811#M485060</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-18T06:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803853#M485064</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Change the AND condition with OR, it can not be 802.1X and MAB.&lt;/P&gt;
&lt;P&gt;Also the Authorz Profile is wrong, choose one of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 07:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3803853#M485064</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-18T07:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3804250#M485066</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/266761"&gt;@socratesp1980&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/529249"&gt;@bern81&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what I am trying to do is to have devices&amp;nbsp;connected to other switches won't match my policy set.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE_POLCY_SET.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30345iE5B10D614D3CC592/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE_POLCY_SET.JPG" alt="ISE_POLCY_SET.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 17:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3804250#M485066</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-02-18T17:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3804484#M485068</link>
      <description>Thats fine. Change and to or and have single profile in authorization. It will do what you want</description>
      <pubDate>Tue, 19 Feb 2019 00:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3804484#M485068</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-19T00:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3806120#M485071</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks Mo!&lt;/P&gt;
&lt;P&gt;could you kindly show me how to achieve that with a&amp;nbsp;&lt;SPAN&gt;single profile in authorization ? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Much appreciate&amp;nbsp;it!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 18:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/3806120#M485071</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-02-20T18:40:39Z</dc:date>
    </item>
  </channel>
</rss>

