<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Conditions missing for authentication policy in 2.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484526#M526616</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a POC for ISE using version 2.3. I'm new to ISE so I apologize if this is an obvious question. I couldn't find anything in the forum or docs either. Ok to the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am following Katherine McNamara's &lt;SPAN style="font-size: 10pt;"&gt;blog post &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/migration-blogpost/8156"&gt;ISE - Dot1x Policy Configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the post she uses a network access condition that matches certificate attributes that then results in specific identity sequences. I like this approach as it would allow us to collapse our corporate and byod SSIDs into one and assign different roles and VLANs starting with which certificate the client has. This is one of our goals with moving to a full NAC solution such as ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issue is when I go to add this condition in my authentication policy the condition is missing. Are there limitations on which conditions can be used where? Was there a change in how conditions work in 2.3? I've skimmed through documentation and the forums and I can't find any mention of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot of the condition:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="network_access_condition.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/111348_network_access_condition.PNG" style="height: 236px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 17 Sep 2017 17:39:01 GMT</pubDate>
    <dc:creator>Charlie Dean</dc:creator>
    <dc:date>2017-09-17T17:39:01Z</dc:date>
    <item>
      <title>Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484526#M526616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a POC for ISE using version 2.3. I'm new to ISE so I apologize if this is an obvious question. I couldn't find anything in the forum or docs either. Ok to the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am following Katherine McNamara's &lt;SPAN style="font-size: 10pt;"&gt;blog post &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/migration-blogpost/8156"&gt;ISE - Dot1x Policy Configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the post she uses a network access condition that matches certificate attributes that then results in specific identity sequences. I like this approach as it would allow us to collapse our corporate and byod SSIDs into one and assign different roles and VLANs starting with which certificate the client has. This is one of our goals with moving to a full NAC solution such as ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issue is when I go to add this condition in my authentication policy the condition is missing. Are there limitations on which conditions can be used where? Was there a change in how conditions work in 2.3? I've skimmed through documentation and the forums and I can't find any mention of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot of the condition:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="network_access_condition.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/111348_network_access_condition.PNG" style="height: 236px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 17:39:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484526#M526616</guid>
      <dc:creator>Charlie Dean</dc:creator>
      <dc:date>2017-09-17T17:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484527#M526618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The right-hand-side (RHS) in this instance is a text input so we simply type in the text string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/videos/16601"&gt; Video Link : 16601 &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 17:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484527#M526618</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-17T17:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484528#M526620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See also the video walk-through of the policy UI in &lt;A href="https://community.cisco.com/docs/DOC-74808"&gt;What's New in ISE 2.3?&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 17:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484528#M526620</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-17T17:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484529#M526622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi. The issue isn't creating the condition. I had our TLD in there, I just blacked it out. The issue is when I try and use the condition in a authentication policy. It doesn't show up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 18:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484529#M526622</guid>
      <dc:creator>Charlie Dean</dc:creator>
      <dc:date>2017-09-17T18:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484530#M526624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-decoration: line-through;"&gt;You can use it in authorization policy rules only.&lt;/SPAN&gt; [Correction] We can't use it in any policy set conditions but we can use it in authentication policy conditions inside a policy set.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="111349" alt="Screen Shot 2017-09-17 at 18.31.15.png" class="image-1 jive-image" src="/legacyfs/online/fusion/111349_Screen Shot 2017-09-17 at 18.31.15.png" style="height: 172px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate attributes are not yet available at that point in determining which protocols to use. It's removed to resolve CSCvc98033.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 18:17:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484530#M526624</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-17T18:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484531#M526626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I think that was the answer I was looking for. Is there a doc I can reference that shows which condition types can be used where in a policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 18:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484531#M526626</guid>
      <dc:creator>Charlie Dean</dc:creator>
      <dc:date>2017-09-17T18:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Conditions missing for authentication policy in 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484532#M526627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please note that I revised my last response. AFAIK it's documented in CSCvc98033 only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Sep 2017 18:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditions-missing-for-authentication-policy-in-2-3/m-p/3484532#M526627</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-17T18:37:01Z</dc:date>
    </item>
  </channel>
</rss>

