<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RBAC in ISE 2.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rbac-in-ise-2-2/m-p/3523969#M519544</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some trouble with RBAC on ISE 2.2.0.470 and I hope somebody can clarify this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need different Network Device Admin groups for different locations. For example Network Device Admin from France should be able to see and edit Network Devices with location France (my own tag) and an admin from Poland should be able to see and edit all devices from Poland.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I created different admin user groups&amp;nbsp; and mapped them with RBAC Policy to default "Network Device Menu Access" view and custom Data groups for different locations, so far it works. But now I have some issues with data access. It doesn't matter which Data Access Privileges I give - users can see all devices or none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example for admin user for Poland. in Data Access Permissions only location "Poland" has "Full Access", all other "no Access". But the user is able to see also all other locations.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="permissions_ise.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/113647_permissions_ise.png" style="height: 538px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="RBAC Policy.png" class="jive-image image-3" src="/legacyfs/online/fusion/113649_RBAC Policy.png" style="height: 116px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="poland.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/113648_poland.PNG" style="height: 254px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As You can see, the user is also able to see all other locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What could be my problem? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Nov 2017 09:38:49 GMT</pubDate>
    <dc:creator>Thomas Schmitt</dc:creator>
    <dc:date>2017-11-24T09:38:49Z</dc:date>
    <item>
      <title>RBAC in ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-in-ise-2-2/m-p/3523969#M519544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some trouble with RBAC on ISE 2.2.0.470 and I hope somebody can clarify this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need different Network Device Admin groups for different locations. For example Network Device Admin from France should be able to see and edit Network Devices with location France (my own tag) and an admin from Poland should be able to see and edit all devices from Poland.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I created different admin user groups&amp;nbsp; and mapped them with RBAC Policy to default "Network Device Menu Access" view and custom Data groups for different locations, so far it works. But now I have some issues with data access. It doesn't matter which Data Access Privileges I give - users can see all devices or none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example for admin user for Poland. in Data Access Permissions only location "Poland" has "Full Access", all other "no Access". But the user is able to see also all other locations.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="permissions_ise.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/113647_permissions_ise.png" style="height: 538px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="RBAC Policy.png" class="jive-image image-3" src="/legacyfs/online/fusion/113649_RBAC Policy.png" style="height: 116px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="poland.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/113648_poland.PNG" style="height: 254px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As You can see, the user is also able to see all other locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What could be my problem? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Nov 2017 09:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-in-ise-2-2/m-p/3523969#M519544</guid>
      <dc:creator>Thomas Schmitt</dc:creator>
      <dc:date>2017-11-24T09:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC in ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/rbac-in-ise-2-2/m-p/3523970#M519548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See my response @ &lt;A _jive_internal="true" href="https://community.cisco.com/thread/87388"&gt;How to segregate device admin access to a device group on ISE&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Nov 2017 22:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rbac-in-ise-2-2/m-p/3523970#M519548</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-26T22:36:12Z</dc:date>
    </item>
  </channel>
</rss>

