<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User Defined attributes for Radius in ISE 2.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-defined-attributes-for-radius-in-ise-2-3/m-p/3438810#M496222</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Community Members,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently doing POC of ISE 2.3 for Radius AAA. We are using AAA to authenticate and authorize Base Stations(BTS) and CPEs.&lt;/P&gt;&lt;P&gt;We have third party vendor(Radwin, Cambium, mrotek etc) devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have successfully achieved authentication and authorization for these devices by creating user defined dictionaries and vendor specific attributes. But now we have a requirement to send(push) multiple attribute values to the endpoints (BTS and CPEs) on the authentication and authorization of different devices based on their MAC or S/N of device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can create and define static value for these attributes but the requirement is to push variable values of multiple attributes, so creating those many Authorization profile doesn't seem feasible option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you please help us out with the solution of how to fetch the MAC address or Serial number and use it to differentiate and assign&amp;nbsp; different multiple values of attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you understand my query, and if not please ask your doubt and i will explain in details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Karan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jul 2018 14:59:22 GMT</pubDate>
    <dc:creator>karandesai32</dc:creator>
    <dc:date>2018-07-12T14:59:22Z</dc:date>
    <item>
      <title>User Defined attributes for Radius in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/user-defined-attributes-for-radius-in-ise-2-3/m-p/3438810#M496222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Community Members,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently doing POC of ISE 2.3 for Radius AAA. We are using AAA to authenticate and authorize Base Stations(BTS) and CPEs.&lt;/P&gt;&lt;P&gt;We have third party vendor(Radwin, Cambium, mrotek etc) devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have successfully achieved authentication and authorization for these devices by creating user defined dictionaries and vendor specific attributes. But now we have a requirement to send(push) multiple attribute values to the endpoints (BTS and CPEs) on the authentication and authorization of different devices based on their MAC or S/N of device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can create and define static value for these attributes but the requirement is to push variable values of multiple attributes, so creating those many Authorization profile doesn't seem feasible option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you please help us out with the solution of how to fetch the MAC address or Serial number and use it to differentiate and assign&amp;nbsp; different multiple values of attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you understand my query, and if not please ask your doubt and i will explain in details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Karan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 14:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-defined-attributes-for-radius-in-ise-2-3/m-p/3438810#M496222</guid>
      <dc:creator>karandesai32</dc:creator>
      <dc:date>2018-07-12T14:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: User Defined attributes for Radius in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/user-defined-attributes-for-radius-in-ise-2-3/m-p/3438811#M496223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can define custom attributes in ISE which are applied to user or endpoints in ISE database.&amp;nbsp; You can then use these custom attributes to apply specific policy and return custom permissions.&amp;nbsp; If the custom attribute itself contains the special value of the permission, say ACL or VLAN name or SGT, then you can often return this as a dynamic authorization.&amp;nbsp; More info on this topic offered in BRKSEC-3697 session delivered at last Cisco Live in Orlando (refer to Reference presentation): &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=brksec-3697#/session/1509501680902001PsTe" title="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=brksec-3697#/session/1509501680902001PsTe"&gt;On-Demand Library - Cisco Live Global Events&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 15:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-defined-attributes-for-radius-in-ise-2-3/m-p/3438811#M496223</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-07-12T15:23:05Z</dc:date>
    </item>
  </channel>
</rss>

