<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Set Condition based off Multiple Locations in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795446#M485550</link>
    <description>&lt;P&gt;Yes thats it, they both work, the bottom one would be preferred.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While it has no impact on the functionality, I also suggest keeping your rules with the same format. Ex location first, then device type, then groups etc. Just makes it easier if you're later auditing, you have an expected order. The order you pick is up entirely up to you if you want to do it that way.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Feb 2019 21:38:41 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-02-05T21:38:41Z</dc:date>
    <item>
      <title>Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795387#M485545</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE v2.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to try and modify an existing Policy Set for Wireless Guest Access. The set I would like to use currently says:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy_Set.png" style="width: 586px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29365iB47E4666E18DBF64/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy_Set.png" alt="Policy_Set.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I would like to do is add new condition so that it basically says that it will match if its either Location1 &lt;STRONG&gt;OR&lt;/STRONG&gt; Location2. How can I achieve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think if I just choose to add a new OR condition, right below Location1, then it would say: If Guest, Guest Flow and Location1 are meet then match it, OR if its Location2 then match it &lt;EM&gt;(*which would I think it would just ignore the Guest and Guest Flow conditions if its in Location2).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 20:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795387#M485545</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-05T20:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795400#M485546</link>
      <description>&lt;P&gt;A quick shuffle will make this work.&amp;nbsp; Use a single "and" with a nested "or" for the locations. Add as many locations as you need within the "or".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;example, I don't have identical fields to you, I just used what was available to demo.&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="authz.PNG" style="width: 834px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29366iE5B1E9DC14FB6FDC/image-dimensions/834x241?v=v2" width="834" height="241" role="button" title="authz.PNG" alt="authz.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 20:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795400#M485546</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-05T20:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795408#M485547</link>
      <description>&lt;P&gt;Thanks Damien!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this look correct to you for what I was explaining?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy_Set.png" style="width: 605px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29367i23400B5FAC6B42D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy_Set.png" alt="Policy_Set.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks Again,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 20:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795408#M485547</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-05T20:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795427#M485548</link>
      <description>&lt;P&gt;It will work, it just has a redundant "and".&amp;nbsp; You can pull the location "or", the network access, and radius conditions out and delete the second and.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Move everything to the same level as the identity group at the bottom.&amp;nbsp; This will leave on the the "or" operand nested under your single "and".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 21:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795427#M485548</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-05T21:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795443#M485549</link>
      <description>&lt;P&gt;Ok, so you're saying I should go from the top one below to the bottom one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy_Set.png" style="width: 544px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29373iCD0AF363E45E6C7C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy_Set.png" alt="Policy_Set.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 21:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795443#M485549</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-05T21:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795446#M485550</link>
      <description>&lt;P&gt;Yes thats it, they both work, the bottom one would be preferred.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While it has no impact on the functionality, I also suggest keeping your rules with the same format. Ex location first, then device type, then groups etc. Just makes it easier if you're later auditing, you have an expected order. The order you pick is up entirely up to you if you want to do it that way.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 21:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795446#M485550</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-05T21:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795490#M485551</link>
      <description>Ok, sounds good. Thanks again for the help!&lt;BR /&gt;&lt;BR /&gt;-Matt</description>
      <pubDate>Tue, 05 Feb 2019 22:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3795490#M485551</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-05T22:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799397#M485552</link>
      <description>&lt;P&gt;Hey Damien,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried getting rid of that extra AND level. But, there didn't seem like an easy way to just drag conditions to an outer level. So I ended up just trying to re-create the condition/policy set. But, after I did I noticed the icon for the Identity Group condition &lt;EM&gt;(*the bottom condition)&lt;/EM&gt; is no longer the same as it was before... Any idea why that is?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Screenshot below:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE_Policy_Set.png" style="width: 600px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29846iE831D2BF9EB31074/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE_Policy_Set.png" alt="ISE_Policy_Set.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this going to be an issue? Not sure why it would do that when I'm selecting the "IdentityGroup" one. When I look at what the circled icon is above in the "select attribute" box that pops up, it says that icon falls under "Unclassified".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 17:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799397#M485552</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-11T17:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799410#M485553</link>
      <description>&lt;P&gt;I believe it a minor bug, affecting UI only, and should not have an impact in policy evaluation.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 18:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799410#M485553</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-11T18:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799421#M485554</link>
      <description>&lt;P&gt;We also have a Guest policy set for our remote branch offices. Basically every other location that we have besides Location 1 and Location 2 use this policy. The only real difference is that instead of using "Locations", it uses Called-Station-ID &lt;EM&gt;(*which we have setup for the WLC to send "AP-Name:SSID")&lt;/EM&gt; so we check the AP name instead of location because I setup all APs in the remote branches to start with the same Prefix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That policy set also had an extra AND level. And when I re-created that one all the icons changed there too...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are these 2 below equivalent?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;OLD:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE_Policy_Set1.png" style="width: 482px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29850iF98C65712FD30CBA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE_Policy_Set1.png" alt="ISE_Policy_Set1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NEW:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE_Policy_Set2.png" style="width: 482px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29851i41ADC3E8263A1E26/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE_Policy_Set2.png" alt="ISE_Policy_Set2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Are those 2 sets above equivalent? Wasn't sure why the top 3 conditions were sort of separated from the bottom condition with the extra "AND"...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks Again,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 18:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799421#M485554</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-11T18:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799443#M485555</link>
      <description>Yes, those two authorization rules will do the same thing, you have to meet all four conditions in either.  Weird display bug hslai mentioned.</description>
      <pubDate>Mon, 11 Feb 2019 18:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799443#M485555</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-11T18:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799444#M485556</link>
      <description>Ok got it. Thanks hslai.&lt;BR /&gt;&lt;BR /&gt;-Matt</description>
      <pubDate>Mon, 11 Feb 2019 18:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799444#M485556</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-11T18:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799445#M485558</link>
      <description>Ok cool, thanks for the confirmation!&lt;BR /&gt;&lt;BR /&gt;-Matt</description>
      <pubDate>Mon, 11 Feb 2019 18:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799445#M485558</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-11T18:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Set Condition based off Multiple Locations</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799447#M485560</link>
      <description>FYI...&lt;BR /&gt;&lt;BR /&gt;After clicking "SAVE" at the bottom of the Policy Sets page, and the page refreshes. The icons change back to what they "should" look like.&lt;BR /&gt;&lt;BR /&gt;-Matt</description>
      <pubDate>Mon, 11 Feb 2019 18:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-set-condition-based-off-multiple-locations/m-p/3799447#M485560</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2019-02-11T18:45:10Z</dc:date>
    </item>
  </channel>
</rss>

