<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3886859#M507114</link>
    <description>&lt;P&gt;i have the same original problem.&lt;/P&gt;&lt;P&gt;we have a ISE 2.4 with Patch 8 installed.&lt;/P&gt;&lt;P&gt;For same reason i can't create a Authorization Policy for the group.&lt;/P&gt;&lt;P&gt;If i assign a custom Tag to the endpoint than i can use that tag in the AuthZ Policy. But we would like to avoid that.&lt;/P&gt;&lt;P&gt;I can only setup a policy against the InternalUser store and note the Endpoints.&lt;/P&gt;&lt;P&gt;The Endpoint Dictionary only gives me the custom field and same others but not the Identity Group.&lt;/P&gt;&lt;P&gt;i attached same screenshots that show the steps&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 07:58:33 GMT</pubDate>
    <dc:creator>janis.heffe</dc:creator>
    <dc:date>2019-07-09T07:58:33Z</dc:date>
    <item>
      <title>MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720397#M507108</link>
      <description>&lt;P&gt;Hi I am trying to enable MAB authentication to allow only a specific group of mac address on the network&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to create a group but not sure how, I have tried in the Endpoint Identity Group but it does seem like it works&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is the picture of what i am trying to do and that is change group wired_mab is using to authenticate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do i add my own group to this list. for example instead of internal endpoint i want the group to be call funky mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 14:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720397#M507108</guid>
      <dc:creator>anson-bates</dc:creator>
      <dc:date>2018-10-06T14:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720424#M507110</link>
      <description>&lt;P&gt;You would need to create an Identity source sequence and then reference Internal Endpoints.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 17:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720424#M507110</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-10-06T17:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720429#M507111</link>
      <description>The issue I am running into is that ISE is dynamically adding MAC address once plugged into a switch port. How do I turn this off&lt;BR /&gt;</description>
      <pubDate>Sat, 06 Oct 2018 17:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720429#M507111</guid>
      <dc:creator>anson-bates</dc:creator>
      <dc:date>2018-10-06T17:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720443#M507113</link>
      <description>&lt;P&gt;I am not entirely sure how you have configured your policy but this is an example of what you could do.&amp;nbsp; Keep in mind that the following will match all wired MAB (and possibly wireless MAB depending on how your Policy set is configured).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. create an Endpoint Identity Group and place the MAC addresses for the MAB clients in this group&lt;/P&gt;
&lt;P&gt;2. Go to Policy Elements &amp;gt; Results and create an authorization result policy for the MAB devices&lt;/P&gt;
&lt;P&gt;3. Go to Policy Sets and edit the MAB policy, if one doesn't exist create a MAB policy Condition should be Wired_MAB and Allowed Protocols should be Default Network Access&lt;/P&gt;
&lt;P&gt;4. Edit the policy you just created and under Authentication Policy create a new policy where the condition is Wired_MAB and under "use" select Internal Endpoints&lt;/P&gt;
&lt;P&gt;5. Under Authorization Policy where the condition matches "Identity Group Name EQUALS Endpoint Identity Groups:&amp;lt;name of identity group that you have created earlier&amp;gt;"&lt;/P&gt;
&lt;P&gt;6. Under "Result: Profiles" select the Authorization result policy you created earlier.&lt;/P&gt;
&lt;P&gt;7. Save the configuration&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 19:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3720443#M507113</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-10-06T19:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3886859#M507114</link>
      <description>&lt;P&gt;i have the same original problem.&lt;/P&gt;&lt;P&gt;we have a ISE 2.4 with Patch 8 installed.&lt;/P&gt;&lt;P&gt;For same reason i can't create a Authorization Policy for the group.&lt;/P&gt;&lt;P&gt;If i assign a custom Tag to the endpoint than i can use that tag in the AuthZ Policy. But we would like to avoid that.&lt;/P&gt;&lt;P&gt;I can only setup a policy against the InternalUser store and note the Endpoints.&lt;/P&gt;&lt;P&gt;The Endpoint Dictionary only gives me the custom field and same others but not the Identity Group.&lt;/P&gt;&lt;P&gt;i attached same screenshots that show the steps&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 07:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3886859#M507114</guid>
      <dc:creator>janis.heffe</dc:creator>
      <dc:date>2019-07-09T07:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3887281#M507115</link>
      <description>Is this something worked before for you?  There are examples of working authorization rules here for endpoint groups&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475#toc-hId--916002297" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475#toc-hId--916002297&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Jul 2019 20:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3887281#M507115</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-07-09T20:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3887557#M507116</link>
      <description>&lt;P&gt;thank you very much.&lt;/P&gt;&lt;P&gt;for same reason i couldn't find it.&lt;/P&gt;&lt;P&gt;It is a new installation and we are in the process of getting ready to migrate from ACS to ISE. We are moving forward to the testing phase.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 08:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/3887557#M507116</guid>
      <dc:creator>janis.heffe</dc:creator>
      <dc:date>2019-07-10T08:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/4578552#M573685</link>
      <description>&lt;P&gt;Sorry to bring up an old thread but did you ever find an answer to this quest? I would greatly appreciate a response. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 14:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication/m-p/4578552#M573685</guid>
      <dc:creator>DHCBT</dc:creator>
      <dc:date>2022-03-25T14:08:46Z</dc:date>
    </item>
  </channel>
</rss>

