<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wired mab authorization to LDAP problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745527#M488308</link>
    <description>ISE is checking the following attributes :&lt;BR /&gt;&lt;BR /&gt;      15048     Queried PIP - TESTLDAP.ExternalGroups&lt;BR /&gt;      15048     Queried PIP - Radius.NAS-Port-Type&lt;BR /&gt;      15048     Queried PIP - EndPoints.LogicalProfile&lt;BR /&gt;      15048     Queried PIP - Network Access.AuthenticationStatus&lt;BR /&gt;&lt;BR /&gt;I would suggest you check the policies configured as well to see if the request matches any of these attributes, may be a screenshot would help.&lt;BR /&gt;</description>
    <pubDate>Tue, 13 Nov 2018 07:08:52 GMT</pubDate>
    <dc:creator>Surendra</dc:creator>
    <dc:date>2018-11-13T07:08:52Z</dc:date>
    <item>
      <title>Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745521#M488304</link>
      <description>&lt;P&gt;Can someone figure out that I configure the LDAP server for ISE authentication of MAB, but the session doesn't hit on the authorization policy of LDAP group, I thought maybe is incorrect value in the * Group Map Attribute or * Group Object Class.. I'm not sure what can I do..&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 273px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23958iAD58F1E7E6B587EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 619px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23959i0020225A1794F730/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23960iFE14B17FDFF70CF4/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.jpg" alt="3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.jpg" style="width: 903px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23961i94CB62B9AA198FE2/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.jpg" alt="4.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.jpg" style="width: 568px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23962iC6EC740D70BE6F59/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.jpg" alt="5.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.jpg" style="width: 846px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23963iF7C72A0A94B6C245/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.jpg" alt="6.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.jpg" style="width: 911px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23964i7F962170E4547D70/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.jpg" alt="7.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23965iA91C8D93A50FA9F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.jpg" alt="8.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23966iA6CD688C452DCE4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.jpg" alt="9.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23967iA667650001BBEEF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="10.jpg" alt="10.jpg" /&gt;&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Overview&lt;/FONT&gt;&lt;BR /&gt;Event &amp;nbsp;&amp;nbsp; &amp;nbsp;5200 Authentication succeeded&lt;BR /&gt;Username &amp;nbsp;&amp;nbsp; &amp;nbsp;00:0C:29:0A:6B:B5&lt;BR /&gt;Endpoint Id &amp;nbsp;&amp;nbsp; &amp;nbsp;00:0C:29:0A:6B:B5&lt;BR /&gt;Endpoint Profile &amp;nbsp;&amp;nbsp; &amp;nbsp;Windows7-Workstation&lt;BR /&gt;Authentication Policy&amp;nbsp;&amp;nbsp; &amp;nbsp;Default &amp;gt;&amp;gt; MAB&lt;BR /&gt;Authorization Policy&amp;nbsp;&amp;nbsp; &amp;nbsp;Default &amp;gt;&amp;gt; Basic_Authenticated_Access&lt;BR /&gt;Authorization Result&amp;nbsp;&amp;nbsp; &amp;nbsp;PermitAccess&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Authentication Details&lt;/FONT&gt;&lt;BR /&gt;Source Timestamp &amp;nbsp;&amp;nbsp; &amp;nbsp; 2018-11-13 14:01:36.191 &lt;BR /&gt;Received Timestamp &amp;nbsp;&amp;nbsp; &amp;nbsp; 2018-11-13 14:01:36.204 &lt;BR /&gt;Policy Server &amp;nbsp;&amp;nbsp; &amp;nbsp; ise1 &lt;BR /&gt;Event &amp;nbsp;&amp;nbsp; &amp;nbsp;5200 Authentication succeeded&lt;BR /&gt;Username &amp;nbsp;&amp;nbsp; &amp;nbsp; 00:0C:29:0A:6B:B5 &lt;BR /&gt;Endpoint Id &amp;nbsp;&amp;nbsp; &amp;nbsp; 00:0C:29:0A:6B:B5 &lt;BR /&gt;Calling Station Id &amp;nbsp;&amp;nbsp; &amp;nbsp; 00-0C-29-0A-6B-B5 &lt;BR /&gt;Endpoint Profile &amp;nbsp;&amp;nbsp; &amp;nbsp; Windows7-Workstation &lt;BR /&gt;IPv4 Address &amp;nbsp;&amp;nbsp; &amp;nbsp; 192.168.92.171 &lt;BR /&gt;Authentication Identity Store &amp;nbsp;&amp;nbsp; &amp;nbsp; TESTLDAP &lt;BR /&gt;Identity Group &amp;nbsp;&amp;nbsp; &amp;nbsp; test-whitelist &lt;BR /&gt;Audit Session Id &amp;nbsp;&amp;nbsp; &amp;nbsp; C0A85C6400000005004ADC22 &lt;BR /&gt;Authentication Method &amp;nbsp;&amp;nbsp; &amp;nbsp; mab &lt;BR /&gt;Authentication Protocol &amp;nbsp;&amp;nbsp; &amp;nbsp; Lookup &lt;BR /&gt;Service Type &amp;nbsp;&amp;nbsp; &amp;nbsp; Call Check &lt;BR /&gt;Network Device &amp;nbsp;&amp;nbsp; &amp;nbsp; CR-2960 &lt;BR /&gt;Device Type &amp;nbsp;&amp;nbsp; &amp;nbsp; All Device Types#switch#SW2960 &lt;BR /&gt;Location &amp;nbsp;&amp;nbsp; &amp;nbsp; All Locations#Yangmei#CR &lt;BR /&gt;NAS IPv4 Address &amp;nbsp;&amp;nbsp; &amp;nbsp; 192.168.92.100 &lt;BR /&gt;NAS Port Id &amp;nbsp;&amp;nbsp; &amp;nbsp; GigabitEthernet0/5 &lt;BR /&gt;NAS Port Type &amp;nbsp;&amp;nbsp; &amp;nbsp; Ethernet &lt;BR /&gt;Authorization Profile &amp;nbsp;&amp;nbsp; &amp;nbsp; PermitAccess &lt;BR /&gt;Response Time &amp;nbsp;&amp;nbsp; &amp;nbsp; 64 milliseconds&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Other Attributes&lt;/FONT&gt;&lt;BR /&gt;ConfigVersionId &amp;nbsp;&amp;nbsp; &amp;nbsp;134&lt;BR /&gt;DestinationPort &amp;nbsp;&amp;nbsp; &amp;nbsp;1645&lt;BR /&gt;Protocol &amp;nbsp;&amp;nbsp; &amp;nbsp;Radius&lt;BR /&gt;NAS-Port &amp;nbsp;&amp;nbsp; &amp;nbsp;50005&lt;BR /&gt;Framed-MTU &amp;nbsp;&amp;nbsp; &amp;nbsp;1500&lt;BR /&gt;OriginalUserName &amp;nbsp;&amp;nbsp; &amp;nbsp;000c290a6bb5&lt;BR /&gt;NetworkDeviceProfileId &amp;nbsp;&amp;nbsp; &amp;nbsp;b0699505-3150-4215-a80e-6753d45bf56c&lt;BR /&gt;IsThirdPartyDeviceFlow &amp;nbsp;&amp;nbsp; &amp;nbsp;false&lt;BR /&gt;AcsSessionID &amp;nbsp;&amp;nbsp; &amp;nbsp;ise1/331133428/16&lt;BR /&gt;UseCase &amp;nbsp;&amp;nbsp; &amp;nbsp;Host Lookup&lt;BR /&gt;SelectedAuthenticationIdentityStores &amp;nbsp;&amp;nbsp; &amp;nbsp;TESTLDAP&lt;BR /&gt;AuthenticationStatus &amp;nbsp;&amp;nbsp; &amp;nbsp;AuthenticationPassed&lt;BR /&gt;IdentityPolicyMatchedRule &amp;nbsp;&amp;nbsp; &amp;nbsp;MAB&lt;BR /&gt;AuthorizationPolicyMatchedRule &amp;nbsp;&amp;nbsp; &amp;nbsp;Basic_Authenticated_Access&lt;BR /&gt;CPMSessionID &amp;nbsp;&amp;nbsp; &amp;nbsp;C0A85C6400000005004ADC22&lt;BR /&gt;EndPointMACAddress &amp;nbsp;&amp;nbsp; &amp;nbsp;00-0C-29-0A-6B-B5&lt;BR /&gt;ISEPolicySetName &amp;nbsp;&amp;nbsp; &amp;nbsp;Default&lt;BR /&gt;IdentitySelectionMatchedRule &amp;nbsp;&amp;nbsp; &amp;nbsp;MAB&lt;BR /&gt;DTLSSupport &amp;nbsp;&amp;nbsp; &amp;nbsp;Unknown&lt;BR /&gt;HostIdentityGroup &amp;nbsp;&amp;nbsp; &amp;nbsp;Endpoint Identity Groups:test-whitelist&lt;BR /&gt;Network Device Profile &amp;nbsp;&amp;nbsp; &amp;nbsp;Cisco&lt;BR /&gt;IPSEC &amp;nbsp;&amp;nbsp; &amp;nbsp;IPSEC#Is IPSEC Device#No&lt;BR /&gt;Name &amp;nbsp;&amp;nbsp; &amp;nbsp;Endpoint Identity Groups:test-whitelist&lt;BR /&gt;IdentityDn &amp;nbsp;&amp;nbsp; &amp;nbsp;cn=000C290A6BB5,ou=OA,ou=MACAddresses,ou=MAC,dc=test,dc=com&lt;BR /&gt;gidNumber &amp;nbsp;&amp;nbsp; &amp;nbsp;503&lt;BR /&gt;uid &amp;nbsp;&amp;nbsp; &amp;nbsp;000c290a6bb5&lt;BR /&gt;RADIUS Username &amp;nbsp;&amp;nbsp; &amp;nbsp;00:0C:29:0A:6B:B5&lt;BR /&gt;Device IP Address &amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.92.100&lt;BR /&gt;Called-Station-ID &amp;nbsp;&amp;nbsp; &amp;nbsp;DC:7B:94:16:53:85&lt;BR /&gt;CiscoAVPair &amp;nbsp;&amp;nbsp; &amp;nbsp; audit-session-id=C0A85C6400000005004ADC22 &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Result&lt;/FONT&gt;&lt;BR /&gt;User-Name &amp;nbsp;&amp;nbsp; &amp;nbsp;00-0C-29-0A-6B-B5&lt;BR /&gt;Class &amp;nbsp;&amp;nbsp; &amp;nbsp;CACS:C0A85C6400000005004ADC22:ise1/331133428/16&lt;BR /&gt;cisco-av-pair &amp;nbsp;&amp;nbsp; &amp;nbsp;profile-name=Windows7-Workstation&lt;BR /&gt;LicenseTypes &amp;nbsp;&amp;nbsp; &amp;nbsp;Base license consumed &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Steps&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;11001 &amp;nbsp;&amp;nbsp; &amp;nbsp;Received RADIUS Access-Request&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;11017 &amp;nbsp;&amp;nbsp; &amp;nbsp;RADIUS created a new session&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;11027 &amp;nbsp;&amp;nbsp; &amp;nbsp;Detected Host Lookup UseCase (Service-Type = Call Check (10))&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15049 &amp;nbsp;&amp;nbsp; &amp;nbsp;Evaluating Policy Group&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15008 &amp;nbsp;&amp;nbsp; &amp;nbsp;Evaluating Service Selection Policy&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15048 &amp;nbsp;&amp;nbsp; &amp;nbsp;Queried PIP - Normalised Radius.RadiusFlowType&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15041 &amp;nbsp;&amp;nbsp; &amp;nbsp;Evaluating Identity Policy&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15013 &amp;nbsp;&amp;nbsp; &amp;nbsp;Selected Identity Source - TESTLDAP&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;24031 &amp;nbsp;&amp;nbsp; &amp;nbsp;Sending request to primary LDAP server - TESTLDAP&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;24017 &amp;nbsp;&amp;nbsp; &amp;nbsp;Looking up host in LDAP Server - TESTLDAP&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;24029 &amp;nbsp;&amp;nbsp; &amp;nbsp;Host's attributes are retrieved - TESTLDAP&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;24005 &amp;nbsp;&amp;nbsp; &amp;nbsp;Host search finished successfully - TESTLDAP&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;22037 &amp;nbsp;&amp;nbsp; &amp;nbsp;Authentication Passed&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;24715 &amp;nbsp;&amp;nbsp; &amp;nbsp;ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15036 &amp;nbsp;&amp;nbsp; &amp;nbsp;Evaluating Authorization Policy&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15048 &amp;nbsp;&amp;nbsp; &amp;nbsp;Queried PIP - TESTLDAP.ExternalGroups&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15048 &amp;nbsp;&amp;nbsp; &amp;nbsp;Queried PIP - Radius.NAS-Port-Type&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15048 &amp;nbsp;&amp;nbsp; &amp;nbsp;Queried PIP - EndPoints.LogicalProfile&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15048 &amp;nbsp;&amp;nbsp; &amp;nbsp;Queried PIP - Network Access.AuthenticationStatus&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;15016 &amp;nbsp;&amp;nbsp; &amp;nbsp;Selected Authorization Profile - PermitAccess&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;11002 &amp;nbsp;&amp;nbsp; &amp;nbsp;Returned RADIUS Access-Accept &lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 06:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745521#M488304</guid>
      <dc:creator>chanyunchang</dc:creator>
      <dc:date>2018-11-13T06:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745527#M488308</link>
      <description>ISE is checking the following attributes :&lt;BR /&gt;&lt;BR /&gt;      15048     Queried PIP - TESTLDAP.ExternalGroups&lt;BR /&gt;      15048     Queried PIP - Radius.NAS-Port-Type&lt;BR /&gt;      15048     Queried PIP - EndPoints.LogicalProfile&lt;BR /&gt;      15048     Queried PIP - Network Access.AuthenticationStatus&lt;BR /&gt;&lt;BR /&gt;I would suggest you check the policies configured as well to see if the request matches any of these attributes, may be a screenshot would help.&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Nov 2018 07:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745527#M488308</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-13T07:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745538#M488311</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Surendra&lt;/P&gt;
&lt;P&gt;I configured the policy to match external group.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.jpg" style="width: 942px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/23969i902D5E0490D2BB47/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.jpg" alt="12.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 07:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745538#M488311</guid>
      <dc:creator>chanyunchang</dc:creator>
      <dc:date>2018-11-13T07:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745546#M488314</link>
      <description>If this is only condition, ISE obviously did not match as it went through other conditions configured in other policies as well.&lt;BR /&gt;Would suggest you to check the authorization policy configured and also test the user groups at Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; LDAP &amp;gt; TESTLDAP &amp;gt; Groups &amp;gt; Select Groups from Directory. See if it returns the OA group for that user. If it does, if the authorization policy has the correct condition and if it still does not work, please reach out to TAC.&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Nov 2018 07:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745546#M488314</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-13T07:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745711#M488319</link>
      <description>&lt;P&gt;Absolutely agree &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt; the ISE match in your case default rule : wich is basic authentication access = permit ip any any&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 12:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/3745711#M488319</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-11-13T12:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wired mab authorization to LDAP problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/4417978#M567857</link>
      <description>&lt;P&gt;He Guys&lt;/P&gt;&lt;P&gt;topic is quite old &amp;amp; solution is probably already found. I can confirm that matching works against entire DN (meaning ExternalGroups is not exactly CN=OA under OU=MacGroups under OU=MAC &amp;amp; so on up. Instead (with equal op) it must be like&amp;nbsp;&lt;SPAN&gt;CN=OA,OU=MACGroups,OU=MAC,DC=test,DC=com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 16:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-authorization-to-ldap-problems/m-p/4417978#M567857</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-06-14T16:27:23Z</dc:date>
    </item>
  </channel>
</rss>

