<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization Profile Reporting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540957#M526772</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay this will be a little venting of a post, but want to ask about a few issues in reporting on ISE authentication activity.&amp;nbsp; In our best practices we have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Every rule in ISE has a unique authorization profile created.&lt;/LI&gt;&lt;LI&gt;Every authorization profile is well named and self documenting using the following standards:&lt;OL&gt;&lt;LI&gt;SSID_&amp;lt;SSID Name&amp;gt;_&amp;lt;Auth Protocol&amp;gt;_&amp;lt;Description&amp;gt;, i.e. SSID_Employee_PEAP_Domain_Computer&lt;/LI&gt;&lt;LI&gt;Wired_MAB_Descption, i.e. Wired_MAB_Printer&lt;/LI&gt;&lt;LI&gt;Wired_Dot1x_&amp;lt;Auth Protocol&amp;gt;_&amp;lt;Description&amp;gt;, i.e. Wired_Dot1x_PEAP_Domain_Computer&lt;/LI&gt;&lt;LI&gt;VPN_&amp;lt;tunnel group/use case&amp;gt;_&amp;lt;Description&amp;gt;, i.e. VPN_Employee_IT_Admins&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this naming convention, we can hide the Authentication Policy and Authorization Policy in the Live Log window as they are irrelevant.&amp;nbsp; The Authorization Profile column tells the user exactly what happened.&amp;nbsp; The Authorization Profile is the result applied to the user and what is important.&amp;nbsp; The rule name is irrelevant, although we name them accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ISE 2.1, I identified a bug (CSCvb46991) in the Context Visibility screen where the Authorization Profile column was putting the rule name in by mistake.&amp;nbsp; It seems like the solution for that bug was to get rid of the Authorization Profile column all together.&amp;nbsp; So instead of fixing the issue, the ability to filter on our well name results isn't an option on the Context Visibility screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the RADIUS authentication reports, you can add the "AZN Policy" (this is a 1.0 name I think... why hasn't this been updated), but you can't filter on that column.&amp;nbsp; Makes no sense why you can't filter on any of the columns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any reasons we can't use Authorization Profiles as filtering conditions in Context Visibility and Reports?&amp;nbsp; It looks silly to customers when they have well named results and they can't use them on all screens when in my mind there is no difficult technical reason behind it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Sep 2017 17:50:02 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-09-11T17:50:02Z</dc:date>
    <item>
      <title>Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540957#M526772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay this will be a little venting of a post, but want to ask about a few issues in reporting on ISE authentication activity.&amp;nbsp; In our best practices we have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Every rule in ISE has a unique authorization profile created.&lt;/LI&gt;&lt;LI&gt;Every authorization profile is well named and self documenting using the following standards:&lt;OL&gt;&lt;LI&gt;SSID_&amp;lt;SSID Name&amp;gt;_&amp;lt;Auth Protocol&amp;gt;_&amp;lt;Description&amp;gt;, i.e. SSID_Employee_PEAP_Domain_Computer&lt;/LI&gt;&lt;LI&gt;Wired_MAB_Descption, i.e. Wired_MAB_Printer&lt;/LI&gt;&lt;LI&gt;Wired_Dot1x_&amp;lt;Auth Protocol&amp;gt;_&amp;lt;Description&amp;gt;, i.e. Wired_Dot1x_PEAP_Domain_Computer&lt;/LI&gt;&lt;LI&gt;VPN_&amp;lt;tunnel group/use case&amp;gt;_&amp;lt;Description&amp;gt;, i.e. VPN_Employee_IT_Admins&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this naming convention, we can hide the Authentication Policy and Authorization Policy in the Live Log window as they are irrelevant.&amp;nbsp; The Authorization Profile column tells the user exactly what happened.&amp;nbsp; The Authorization Profile is the result applied to the user and what is important.&amp;nbsp; The rule name is irrelevant, although we name them accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ISE 2.1, I identified a bug (CSCvb46991) in the Context Visibility screen where the Authorization Profile column was putting the rule name in by mistake.&amp;nbsp; It seems like the solution for that bug was to get rid of the Authorization Profile column all together.&amp;nbsp; So instead of fixing the issue, the ability to filter on our well name results isn't an option on the Context Visibility screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the RADIUS authentication reports, you can add the "AZN Policy" (this is a 1.0 name I think... why hasn't this been updated), but you can't filter on that column.&amp;nbsp; Makes no sense why you can't filter on any of the columns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any reasons we can't use Authorization Profiles as filtering conditions in Context Visibility and Reports?&amp;nbsp; It looks silly to customers when they have well named results and they can't use them on all screens when in my mind there is no difficult technical reason behind it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 17:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540957#M526772</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-11T17:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540958#M526773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is odd that AuthZ Profile removed, but you can add it back by creating a new view with the Authentication attributes set and adding the SelectedAuthorizationProfiles attribute.&amp;nbsp; I will copy PM on visibility on this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/111171_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 19:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540958#M526773</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-11T19:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540959#M526775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh thanks for that tip Craig.  Never thought about creating a new view.  If the AZN Policy column was searchable in reports then we would be back in business.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 19:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540959#M526775</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-11T19:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540960#M526777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you mean AZN profiles instead of AZN policy as the latter implies Authorization rule and can already be filtered?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-09-12 at 16.56.51.png" class="image-1 jive-image" height="270" src="/legacyfs/online/fusion/111219_Screen Shot 2017-09-12 at 16.56.51.png" style="height: 269.87px; width: 496px;" width="496" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 17:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540960#M526777</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-12T17:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540961#M526778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Authorization rule is the rule name not the applied Authorization Policy.  I should be able to filter on the policy but can't&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 17:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540961#M526778</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-12T17:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540962#M526779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I forwarded your request to enable filtering on authorization profiles to our internal teams. My guess is that any additional filters come with a cost of indexing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2017 02:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540962#M526779</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-13T02:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540963#M526780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CSCvf95756 opened on the request to allow filtering on Authorization Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As part of CSCvb46991, we found in ISE 2.1&lt;/P&gt;&lt;P&gt;that the column "Authorization Profile" displaying "Authorization Policy (rule name)" and&lt;/P&gt;&lt;P&gt;that the column "SelectedAuthorizationProfiles" mapping to "Authorization Profiles".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fix corrected the column/field names:&lt;/P&gt;&lt;P&gt;Authorization Policy --&amp;gt; Authentication Policy (rule name)&lt;/P&gt;&lt;P&gt;Authorization Profile --&amp;gt; Authorization Policy (rule name)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2017 05:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540963#M526780</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-14T05:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540964#M526781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the Context Visibility-&amp;gt;Endpoints is functioning as design and we can’t add in authorization profile without building a custom view?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they can allow is to filter in the reports though that will be very nice.  Most times we are looking at data in live logs or the reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2017 05:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540964#M526781</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-14T05:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Profile Reporting</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540965#M526782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct or at least for now, regarding the built-in views have fix sets of fields.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2017 06:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-reporting/m-p/3540965#M526782</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-14T06:06:20Z</dc:date>
    </item>
  </channel>
</rss>

