<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSCvg04576  fix release , in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cscvg04576-fix-release/m-p/3446775#M520570</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;I have a question from an &lt;/SPAN&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;organization&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;, has around 400 branches, at the moment they used a policy to make sure that employees belonging to a certain branch are connected to it, the policy they used to match device location and AD attribute ( different per branch ) to make sure that users who connects are to correct branch ( AD attribute )&amp;nbsp; and connected to switch allocated in this branch ( device location group), the policy was working fine until they upgraded from 1.2 to 2.2, they hit&amp;nbsp; CSCvg04576 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt; (&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;AD:ExternalGroups NOT_CONTAINS DEVICE:Parameter doesn't work and always true), and as per TAC this bug will be on 1.3 onward,&lt;/SPAN&gt; &lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt;my question&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-indent: -.25in;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;1-&amp;nbsp;&amp;nbsp;&amp;nbsp; 1- &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt;Do have any fix release for&amp;nbsp; CSCvg04576 &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;or it will be supported on upcoming ISE versions ?,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;2-&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Any workaround would be appreciated,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Aug 2019 09:22:50 GMT</pubDate>
    <dc:creator>Sherif El Shourafah</dc:creator>
    <dc:date>2019-08-18T09:22:50Z</dc:date>
    <item>
      <title>CSCvg04576  fix release ,</title>
      <link>https://community.cisco.com/t5/network-access-control/cscvg04576-fix-release/m-p/3446775#M520570</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;I have a question from an &lt;/SPAN&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;organization&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;, has around 400 branches, at the moment they used a policy to make sure that employees belonging to a certain branch are connected to it, the policy they used to match device location and AD attribute ( different per branch ) to make sure that users who connects are to correct branch ( AD attribute )&amp;nbsp; and connected to switch allocated in this branch ( device location group), the policy was working fine until they upgraded from 1.2 to 2.2, they hit&amp;nbsp; CSCvg04576 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt; (&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;AD:ExternalGroups NOT_CONTAINS DEVICE:Parameter doesn't work and always true), and as per TAC this bug will be on 1.3 onward,&lt;/SPAN&gt; &lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt;my question&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-indent: -.25in;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;1-&amp;nbsp;&amp;nbsp;&amp;nbsp; 1- &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; background: white;"&gt;Do have any fix release for&amp;nbsp; CSCvg04576 &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;or it will be supported on upcoming ISE versions ?,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;2-&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Any workaround would be appreciated,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 09:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscvg04576-fix-release/m-p/3446775#M520570</guid>
      <dc:creator>Sherif El Shourafah</dc:creator>
      <dc:date>2019-08-18T09:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvg04576  fix release ,</title>
      <link>https://community.cisco.com/t5/network-access-control/cscvg04576-fix-release/m-p/3446776#M520571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First to add responses already provided by Hsing...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"AFAIK this is by the current design. The only workaround is to use memberOf attribute but that works with direct members only and not primary groups and could incur performance impact.&amp;nbsp; I would recommend to add and use a specific attribute for the customer use case, instead of trying to match group names.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The AD runtime in ISE 1.3 moved to a new implementation such that we are using SIDs for groups instead of the names to be more efficient. Thus, I consider this a bug to address by roadmap(s) and would need PM involvement."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend the use of a specific attribute that matches location as defined by ISE Network Device Groups.&amp;nbsp; This way you could have a single policy rule that is similar to the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IF Device:Location EQUALS AD1:Location"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would allow you to control network access based on the NAD location of user (matched to their location defined in AD/LDAP).&amp;nbsp; You could also try using AD LDAP which I think is the same suggestion by Hsing to use memberOf.&amp;nbsp; A cleaner method would be to use attribute like AD Location which is an Indexed attribute in AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscvg04576-fix-release/m-p/3446776#M520571</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-23T19:03:45Z</dc:date>
    </item>
  </channel>
</rss>

