<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Query specific AD group using certificate common name in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554001#M511018</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I check if an username retrieved from the certificate common name belongs to a specific AD group? In the policy set I can match against the general AD as an external group object &lt;SPAN style="font-size: 13.3333px;"&gt;(have a look at the attached screenshot) &lt;/SPAN&gt;so ISE performs a lookup among all AD groups&amp;nbsp; but, is it possible to reference the exact AD group?&lt;/P&gt;&lt;P&gt;I need to create different &lt;SPAN style="font-size: 13.3333px;"&gt;authorization rules for &lt;/SPAN&gt;my 802.1x wireless clients based on the AD group they belong to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Apr 2018 13:54:59 GMT</pubDate>
    <dc:creator>Antonio Macia</dc:creator>
    <dc:date>2018-04-05T13:54:59Z</dc:date>
    <item>
      <title>Query specific AD group using certificate common name</title>
      <link>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554001#M511018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I check if an username retrieved from the certificate common name belongs to a specific AD group? In the policy set I can match against the general AD as an external group object &lt;SPAN style="font-size: 13.3333px;"&gt;(have a look at the attached screenshot) &lt;/SPAN&gt;so ISE performs a lookup among all AD groups&amp;nbsp; but, is it possible to reference the exact AD group?&lt;/P&gt;&lt;P&gt;I need to create different &lt;SPAN style="font-size: 13.3333px;"&gt;authorization rules for &lt;/SPAN&gt;my 802.1x wireless clients based on the AD group they belong to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554001#M511018</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2018-04-05T13:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Query specific AD group using certificate common name</title>
      <link>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554002#M511019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ISE is of 2.x and fresh install, then there should be a Preloaded_Certificate_Profile with Use Identity From set to Subject - Common Name. If this is not there, you may create one with similar settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, select it for authentication and the AD group/attribute lookups in authorization will be using the common name field as the username.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="116341" alt="Screen Shot 2018-04-05 at 7.21.40 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/116341_Screen Shot 2018-04-05 at 7.21.40 AM.png" style="height: 258px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW... I do not think your existing condition would work well as the AD external groups in ISE 1.3+ are represented in SIDs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 14:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554002#M511019</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-05T14:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Query specific AD group using certificate common name</title>
      <link>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554003#M511020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CAP that Hsing mentions is how you identify what attribute in the certificate is used for identity (i.e. Common Name, etc). If you want to check that credential against your AD as part of the Authentication stage, you would also need to select your AD in the Identity Store dropdown box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can provide differentiated access for different AD user groups in the Authorisation Policy using the &amp;lt;AD&amp;gt;:ExternalGroups EQUALS &amp;lt;group&amp;gt; attribute.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-04-06 at 9.11.34 am.png" class="image-1 jive-image" src="/legacyfs/online/fusion/116381_Screen Shot 2018-04-06 at 9.11.34 am.png" style="height: 152px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Regards&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2018 00:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554003#M511020</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-06T00:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Query specific AD group using certificate common name</title>
      <link>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554004#M511021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Gregory and hslai. &lt;/P&gt;&lt;P&gt;I was creating the AuthZ conditions from the Policy Set menu instead from the Library Conditions and couldn't find the group selection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2018 15:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-specific-ad-group-using-certificate-common-name/m-p/3554004#M511021</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2018-04-16T15:57:19Z</dc:date>
    </item>
  </channel>
</rss>

