<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic Variable Matching Identity Group Description in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3697060#M494606</link>
    <description>&lt;P&gt;In my installs I always allow for a whitelist called Remedate_Later that we put MAC addresses into that we can't easily figure out.&amp;nbsp; This allows us to move out of Monitor mode quicker.&amp;nbsp; On a larger install I want to lock the Remediate_Later concept down to sites, but I don't want to create all the corresponding MAB rules.&amp;nbsp; I am trying to get dynamic variable matching to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I have endpoint identity groups configured as Remediate_Later_&amp;lt;Site Name&amp;gt; and I put the site code in the description field, i.e. Site1.&amp;nbsp; All the network devices names at the site start with Site1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my dynamic variable match I say:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network Access:network device name starts with Identity Group:description&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can make that condition but it doesn't seem to work.&amp;nbsp; I can see in the step data that the PIPs are being queried.&amp;nbsp; I can't use other fields like device location or identity group name because they contain the full path the object, i.e. Identity Groups:Whitelists:Remediate_Later:Remedidate_Later_&amp;lt;Site Name&amp;gt; or All Locations#&amp;lt;Site Name&amp;gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping the description field would be coded straight up as the string I put in.&amp;nbsp; Should this work?&amp;nbsp; I am guessing no one in Dev ever thought of this use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other ideas to accomplish without righting 100s of MAB rules.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Aug 2018 15:00:52 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-08-29T15:00:52Z</dc:date>
    <item>
      <title>Dynamic Variable Matching Identity Group Description</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3697060#M494606</link>
      <description>&lt;P&gt;In my installs I always allow for a whitelist called Remedate_Later that we put MAC addresses into that we can't easily figure out.&amp;nbsp; This allows us to move out of Monitor mode quicker.&amp;nbsp; On a larger install I want to lock the Remediate_Later concept down to sites, but I don't want to create all the corresponding MAB rules.&amp;nbsp; I am trying to get dynamic variable matching to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I have endpoint identity groups configured as Remediate_Later_&amp;lt;Site Name&amp;gt; and I put the site code in the description field, i.e. Site1.&amp;nbsp; All the network devices names at the site start with Site1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my dynamic variable match I say:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network Access:network device name starts with Identity Group:description&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can make that condition but it doesn't seem to work.&amp;nbsp; I can see in the step data that the PIPs are being queried.&amp;nbsp; I can't use other fields like device location or identity group name because they contain the full path the object, i.e. Identity Groups:Whitelists:Remediate_Later:Remedidate_Later_&amp;lt;Site Name&amp;gt; or All Locations#&amp;lt;Site Name&amp;gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was hoping the description field would be coded straight up as the string I put in.&amp;nbsp; Should this work?&amp;nbsp; I am guessing no one in Dev ever thought of this use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other ideas to accomplish without righting 100s of MAB rules.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 15:00:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3697060#M494606</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-29T15:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Variable Matching Identity Group Description</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3699230#M494607</link>
      <description>&lt;P&gt;Identity Group:description does not appear fetching its value at all.&lt;/P&gt;
&lt;P&gt;Instead,&amp;nbsp;it's working ok with an endpoint attribute:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network Access·NetworkDeviceName Starts With&amp;nbsp;EndPoints·assetTag&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 21:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3699230#M494607</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-01T21:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Variable Matching Identity Group Description</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3702904#M494608</link>
      <description>Hsing,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I just got around to testing this today.  I created a custom endpoint attribute called Asset-Location.  I then put the location name in that field.  I was then able to match "Network Device:Location contains Endpoint:Asset-Location".  Thanks for the solution.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Now when I put my endpoints into my whitelist I can lock them into a particular location without having to create a bunch of rules.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Sep 2018 13:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-variable-matching-identity-group-description/m-p/3702904#M494608</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-07T13:52:34Z</dc:date>
    </item>
  </channel>
</rss>

