<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB Endpoint ID groups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-endpoint-id-groups/m-p/3480898#M536996</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried in the lab recently &lt;SPAN style="font-size: 10pt;"&gt;to use MAB to put different sets of devices into the correct SGT group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We created an Endpoint ID Group, and added in the devices to it (mac address, device type, and ID group).&amp;nbsp; We then created an Auth Condition to reference this condition, and finally an Auth Policy rule using the condition.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;However we did not get consistent results – it seems that sometimes the device was picked up by this rule, sometimes not.&amp;nbsp; At one point the profiling service picked up the devices with the mac address in a different format, so we tried disabling profiling and adding in the devices manually.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Do you have a view on the correct way to do this ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ran out of time in the lab, so at the moment can't troubleshoot further, but wanted to be prepared for when we try again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Nov 2016 17:46:54 GMT</pubDate>
    <dc:creator>jrowling</dc:creator>
    <dc:date>2016-11-14T17:46:54Z</dc:date>
    <item>
      <title>MAB Endpoint ID groups</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-endpoint-id-groups/m-p/3480898#M536996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried in the lab recently &lt;SPAN style="font-size: 10pt;"&gt;to use MAB to put different sets of devices into the correct SGT group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We created an Endpoint ID Group, and added in the devices to it (mac address, device type, and ID group).&amp;nbsp; We then created an Auth Condition to reference this condition, and finally an Auth Policy rule using the condition.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;However we did not get consistent results – it seems that sometimes the device was picked up by this rule, sometimes not.&amp;nbsp; At one point the profiling service picked up the devices with the mac address in a different format, so we tried disabling profiling and adding in the devices manually.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Do you have a view on the correct way to do this ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ran out of time in the lab, so at the moment can't troubleshoot further, but wanted to be prepared for when we try again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2016 17:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-endpoint-id-groups/m-p/3480898#M536996</guid>
      <dc:creator>jrowling</dc:creator>
      <dc:date>2016-11-14T17:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: MAB Endpoint ID groups</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-endpoint-id-groups/m-p/3480899#M536997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The lab should have instructions on that. Were you able to get the instructions from the lab?&lt;/P&gt;&lt;P&gt;When you create an endpoint, you can statically assign the endpoint to that group or dynamically.&lt;/P&gt;&lt;P&gt;if you want to statically assign the groups, you need to click on the option as you create the end point to assign to a group.&lt;/P&gt;&lt;P&gt;Once that is done, you can go to the authorization policy and make sure the most restrictive policy is on the top and least restrictive is at the bottom so that ISE can choose the right authorization policy when it profiles an endpoint dynamically&lt;/P&gt;&lt;P&gt;Please take a look at the profiling section of the ISE design guides to understand more on how it works.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64012"&gt;ISE Design &amp;amp;amp; Integration Guides&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2016 03:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-endpoint-id-groups/m-p/3480899#M536997</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2016-11-15T03:12:19Z</dc:date>
    </item>
  </channel>
</rss>

