<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE selecting wrong Device Admin Policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466065#M517527</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears not to do this. It always goes to the same policy linked to the most specific IP. I can't find what's wrong so I decided to open a ticket with support!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Mar 2018 17:27:37 GMT</pubDate>
    <dc:creator>Jeroen1001</dc:creator>
    <dc:date>2018-03-07T17:27:37Z</dc:date>
    <item>
      <title>ISE selecting wrong Device Admin Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466063#M517522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear expert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm talking about the section under &lt;EM&gt;Work Centers &amp;gt; Device Administration &amp;gt; Device Admin Policy Sets&lt;/EM&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our setup, the device is present under 2&amp;nbsp; distinct Network Device Groups. One time using a supernet /24 (management subnet) and one time using a /32. This /32 is the devices' host address which is also part of the supernet of course .&lt;EM&gt;I'm talking about the section Administration &amp;gt; Network Device Groups&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears ISE selects the Device Admin Policy based the most specific prefix.&lt;STRONG&gt; So the policy with the /32 will always win.&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;However, I want it to select the policy&lt;STRONG&gt; based on the order in which it is defined&lt;/STRONG&gt; at Work Centers &amp;gt; Device Administration &amp;gt; Device Admin Policy Sets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically I want it to cycle through the defined policies like an ACL. &lt;/P&gt;&lt;P&gt;- Check first policy. No Match? Check second policy and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please explain how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks in advance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 15:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466063#M517522</guid>
      <dc:creator>Jeroen1001</dc:creator>
      <dc:date>2018-02-28T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE selecting wrong Device Admin Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466064#M517525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default ISE always match first rule match applied.If first not match it continue to the next rule and etc.&lt;/P&gt;&lt;P&gt;It is important how you order rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2018 09:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466064#M517525</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-03-01T09:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE selecting wrong Device Admin Policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466065#M517527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears not to do this. It always goes to the same policy linked to the most specific IP. I can't find what's wrong so I decided to open a ticket with support!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-selecting-wrong-device-admin-policy/m-p/3466065#M517527</guid>
      <dc:creator>Jeroen1001</dc:creator>
      <dc:date>2018-03-07T17:27:37Z</dc:date>
    </item>
  </channel>
</rss>

