<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stack-member ISE condition in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701771#M494050</link>
    <description>&lt;P&gt;Thank you very much Paul. I will follow your recommendation.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 06:42:20 GMT</pubDate>
    <dc:creator>dirksmit</dc:creator>
    <dc:date>2018-09-06T06:42:20Z</dc:date>
    <item>
      <title>Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701197#M494045</link>
      <description>&lt;P&gt;Is it possible to use the switch stack membership in an ISE condition. My customer wants to treat authentication differently depending on a stack membership&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 13:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701197#M494045</guid>
      <dc:creator>dirksmit</dc:creator>
      <dc:date>2018-09-05T13:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701233#M494047</link>
      <description>&lt;P&gt;What is the use case here?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no RADIUS attribute passed to ISE that says "this is a stacked switch".&amp;nbsp; You could infer stacking by looking at the NAD Port ID starting with 2/, 3/ or something like that but that wouldn't help as 1/ could be a stack or stand alone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If they truly want to do this, they should build a custom NDG group in ISE called "Stacked" and have two sub-NDGs called "Yes" and "No".&amp;nbsp; When the add the switch into ISE they set the stacked NDG value correct and use it in their rules.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701233#M494047</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-05T14:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701507#M494049</link>
      <description>An alterntive way around this could be unstacking the switches and giving them each their own management IP.  Then going down the same path as Paul, placing them in different device groups to leverage in the policy sets.</description>
      <pubDate>Wed, 05 Sep 2018 20:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701507#M494049</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-09-05T20:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701771#M494050</link>
      <description>&lt;P&gt;Thank you very much Paul. I will follow your recommendation.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 06:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701771#M494050</guid>
      <dc:creator>dirksmit</dc:creator>
      <dc:date>2018-09-06T06:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701772#M494051</link>
      <description>&lt;P&gt;with your recommendation I meant :&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;There is no RADIUS attribute passed to ISE that says "this is a stacked switch".&amp;nbsp; You could infer stacking by looking at the NAD Port ID starting with 2/, 3/ or something like that but that wouldn't help as 1/ could be a stack or stand alone&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 06:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701772#M494051</guid>
      <dc:creator>dirksmit</dc:creator>
      <dc:date>2018-09-06T06:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701802#M494052</link>
      <description>&lt;P&gt;Be very carefull with using interface id's for anything in a stack, if you have to rebuild the stack, or change a switch in the stack, you run the risk of the numbering changing if you are not careful. Not running stacks is a much better solution to this.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 07:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701802#M494052</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2018-09-06T07:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701807#M494053</link>
      <description>&lt;P&gt;Thank you Jan for your warning. Bedankt Jan voor de waarschuwing. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 07:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3701807#M494053</guid>
      <dc:creator>dirksmit</dc:creator>
      <dc:date>2018-09-06T07:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702066#M494054</link>
      <description>&lt;P&gt;There is an attribute on the Catalyst switch that can be manipulated to send custom string if the IOS is of later version. You can modify the NAS-ID (Attribute 32) with following command:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;SWITCH(config)#&lt;STRONG&gt;radius-server attribute 32 include-in-access-req format ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;LINE&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;A string where %i = IP address and %h = hostname, %d = domain name&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;SWITCH(config)#&lt;STRONG&gt;radius-server attribute 32 include-in-access-req format Stack-%h&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Above will prefix the NAS-ID with 'Stack-' and the switch hostname and send it along during authentication. Once this is done for all stacked switches, simply create a policy set or rule in ISE that leverages the condition, such as If NAS-ID starts with 'Stack-' then do X.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 13:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702066#M494054</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-09-06T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702071#M494055</link>
      <description>&lt;P&gt;Great tip!&amp;nbsp; Learned something new today.&amp;nbsp; I can take the rest of the day off now.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 13:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702071#M494055</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-06T13:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Stack-member ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702074#M494056</link>
      <description>&lt;P&gt;Thank you very much howon. This is the ultimate solution to my question. I will use this in my POC and in a few weeks will let you know how this worked for me.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 14:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/stack-member-ise-condition/m-p/3702074#M494056</guid>
      <dc:creator>dirksmit</dc:creator>
      <dc:date>2018-09-06T14:03:14Z</dc:date>
    </item>
  </channel>
</rss>

