<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE should not use default policy set for dot1x auth! in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597696#M528721</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kadir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Policy Sets in ISE are like the Service Selection Policy on ACS. The order is very important.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please place you Policy Set "Access Wired" before the Default Policy Set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Jul 2017 12:27:55 GMT</pubDate>
    <dc:creator>B. BELHADJ</dc:creator>
    <dc:date>2017-07-03T12:27:55Z</dc:date>
    <item>
      <title>ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597695#M528719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;Hello together,&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;I have configured a wired LAN authentication and I have fully configured the switches, the policies are according to documentations and everything I could think of seems to be set correctly.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;Now the issue is, when I connect my devices (using LAN cables) to the switches, the default policy is being selected (see Screenshot -&amp;gt; Authentication Policy), even though "Radius NAS-PORT-TYPE = Ethernet &amp;amp; Device Type = Device Group Switches (my radius switches)!&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;&lt;IMG alt="Screen Shot 2017-07-03 at 09.51.24.png" class="image-1 jive-image" src="/legacyfs/online/fusion/108843_Screen Shot 2017-07-03 at 09.51.24.png" style="height: 60px; width: 620px;" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;&lt;IMG alt="Screen Shot 2017-07-03 at 09.44.12.png" class="jive-image image-2" src="/legacyfs/online/fusion/108844_Screen Shot 2017-07-03 at 09.44.12.png" style="height: 240px; width: 620px;" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;&lt;SPAN style="color: #333333; font-family: Arial, sans-serif; font-size: 14.399999618530273px;"&gt;Question: How do I disable the default policy or how to ensure that my wired policy is always used for wired dot1x?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 09:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597695#M528719</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-07-03T09:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597696#M528721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kadir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Policy Sets in ISE are like the Service Selection Policy on ACS. The order is very important.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please place you Policy Set "Access Wired" before the Default Policy Set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597696#M528721</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T12:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597697#M528723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Abdollah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have moved around the policy set from top to bottom...technically the "Access Wired" Policy set is at the very top, whereas the default policy set is at the bottom (not moveable anyway)...do you have another sugestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kadir &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597697#M528723</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-07-03T12:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597698#M528725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kadir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please upload a screenshot of your Policy Sets on ISE. I can help based on what you have in your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597698#M528725</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T12:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597699#M528728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to match on dot1x connectivity you need to add the radius attribute&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: 13px; background-color: #f9f9fc;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: 13px; background-color: #f9f9fc;"&gt;Radius:Service-Type = Framed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="margin-bottom: 6px; padding-top: 5px; padding-bottom: 5px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #525252;"&gt;Radius Attribute Authentication type:&lt;/P&gt;&lt;P&gt;&lt;A name="wp387422" style="font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #007fab;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;Framed-User (2) = 802.1X&lt;/P&gt;&lt;P&gt;&lt;A name="wp387423" style="font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #007fab;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;Call-Check (10) = MAB&lt;/P&gt;&lt;P&gt;&lt;A name="wp387424" style="font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #007fab;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;Outbound (5) = Wired WebAuth&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;HTH,&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="margin-bottom: 6px; padding-left: 23px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b; text-indent: -24px;"&gt;Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597699#M528728</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2017-07-03T12:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597700#M528730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope this helps...let me know if required more...&lt;/P&gt;&lt;P&gt;&lt;IMG alt="policy set.PNG" class="image-1 jive-image" src="/legacyfs/online/fusion/108845_policy set.PNG" style="height: 215px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597700#M528730</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-07-03T12:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597701#M528734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even when I add the Service-Type = Framed it uses the default policy...I have multiple Policy sets however it's only the "Access Wired" which is not being recognized for some reason...(see screenshot)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 13:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597701#M528734</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-07-03T13:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597702#M528738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would remove radius attributes first and try to match based on your device type only, perhaps even narrow it down to a specific device your endpoint is hanging off of , k&lt;SPAN style="font-size: 10pt;"&gt;eep it to a minimum and simple just to make sure you hit the policy set at first.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 13:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597702#M528738</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2017-07-03T13:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597703#M528743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suggest the following configuration :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The SSP Access wired must have as condition: &lt;STRONG&gt;Network Access: Protocol EQUALS RADIUS&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Create a new compound condition like &lt;STRONG&gt;New_Created_Compound_Condition &lt;/STRONG&gt; with: &lt;STRONG&gt;Network Access: EapAuthentication Equals EAP-TLS&lt;/STRONG&gt; and &lt;STRONG&gt;Certificate: SibjectAlternativeName – DNS Contains&lt;/STRONG&gt; &lt;EM&gt;your_domain_name&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;In your Authentication Policy &lt;STRONG&gt;AD_Cert&lt;/STRONG&gt; choose as condition (If): &lt;STRONG&gt;New_Created_Compound_Condition&lt;/STRONG&gt; ==&amp;gt; Use &lt;STRONG&gt;AD_Cert_User&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;I suppose that the Certificate Authentication Profile &lt;STRONG&gt;AD_Cert_User&lt;/STRONG&gt; is configured like that: &lt;STRONG&gt;Identity Store: [Not applicable] &lt;/STRONG&gt;and&lt;STRONG&gt; Certificate Attribute: Subject Alternative Name&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Also:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure the Authorization Plicy like that: AthZ_Policy_Name if Any and&lt;/P&gt;&lt;P&gt;CERTIFICAT: Subject Alternative Name – DNS&amp;nbsp; contains “your_domain”&lt;/P&gt;&lt;P&gt;Network Access: AuthenticationMethod Equals X509_PKI&lt;/P&gt;&lt;P&gt;RADIUS: NAS-Poirt-Type Equals ETHERNET&lt;/P&gt;&lt;P&gt;Then: Admin_Wired&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 13:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597703#M528743</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T13:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597704#M528746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The Admin_Wired must be configured like that :&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;VLAN Tag ID 1 and Name: YOUR_VLAN_NAME&lt;/P&gt;&lt;P&gt;You can also enable the rethentication after 1h (as an example): &lt;/P&gt;&lt;P&gt;Reauthentication Timer: 3600&lt;/P&gt;&lt;P&gt;Maintain Connectivity During Reauthentication RADIUS-Request&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 13:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597704#M528746</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T13:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597705#M528749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was the right answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, it now does work after creating a new Policy Set and by using some of your suggested method.&lt;/P&gt;&lt;P&gt;However after removing the (&lt;SPAN style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Device Type = Device Group Switches) and only setting it to Network Access = Radius &amp;amp; Nas-Port-Type = Ethernet...it started Running again!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Thanks you all for the professional help!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 14:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597705#M528749</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-07-03T14:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE should not use default policy set for dot1x auth!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597706#M528752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kadir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm happy to know that you are able know to authenticate the users! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 15:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-should-not-use-default-policy-set-for-dot1x-auth/m-p/3597706#M528752</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T15:56:19Z</dc:date>
    </item>
  </channel>
</rss>

