<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Matching the proper CP policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/matching-the-proper-cp-policy/m-p/3591863#M535417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;As you said, users can match both policies.&amp;nbsp; For CP it should be first match but Posture policy could be match all.&amp;nbsp; Have you considered adding "AND NOT member of BYOD group" to avoid conflicts?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2017 11:16:11 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-08-07T11:16:11Z</dc:date>
    <item>
      <title>Matching the proper CP policy</title>
      <link>https://community.cisco.com/t5/network-access-control/matching-the-proper-cp-policy/m-p/3591862#M535412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if anyone has experienced the following. In the client provisioning policy, I've created 2 different policies i.e. 1 for Corporate machines with Windows and 1 for BYOD devices with Windows. Somehow the devices are picking either one of the policy only. Please find the configured CP policies below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;BYOD-Windows&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Identity Group&lt;/STRONG&gt; - Any&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Operating System&lt;/STRONG&gt; - Windows All&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Conditions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD Group - BYOD Users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Radius:NAS-Port-Type EQUALS Wireless-IEEE 802.11&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result - &lt;/STRONG&gt;WebAgent 4.9.5.8, WinSPWizard 2.2.0.52 and Corporate-NSP-BYOD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Corporate-Windows&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Identity Group&lt;/STRONG&gt; - Any&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Operating System&lt;/STRONG&gt; - Windows All&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Conditions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD Group - Domain Users&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Radius:NAS-Port-Type EQUALS Wireless-IEEE 802.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;Result&lt;/STRONG&gt; - NACAgent 4.9.5.8 AND ComplianceModule 3.6.11098.2&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When I do get the Web Agent on the BYOD devices, I also notice that the endpoint is scanned for the Corporate Security Requirements as well (instead of the BYOD Security Requirements only). But this is definitely due to the user being in 2 of the AD external groups (BYOD user and Domain User). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Any help would be appreciated.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Other info:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Currently running &lt;STRONG&gt;ISE 2.1 patch 3&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ryan &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 05:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/matching-the-proper-cp-policy/m-p/3591862#M535412</guid>
      <dc:creator>ryan.chen</dc:creator>
      <dc:date>2017-08-07T05:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Matching the proper CP policy</title>
      <link>https://community.cisco.com/t5/network-access-control/matching-the-proper-cp-policy/m-p/3591863#M535417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;As you said, users can match both policies.&amp;nbsp; For CP it should be first match but Posture policy could be match all.&amp;nbsp; Have you considered adding "AND NOT member of BYOD group" to avoid conflicts?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 11:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/matching-the-proper-cp-policy/m-p/3591863#M535417</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-07T11:16:11Z</dc:date>
    </item>
  </channel>
</rss>

