<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - C3PL or legacy style ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485784#M538744</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we provide any best practise advice on this subject ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer in this case needs to know if C3PL is the right way to go or not ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;br,&lt;/P&gt;&lt;P&gt;Tue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 May 2016 12:37:58 GMT</pubDate>
    <dc:creator>tuenoerg</dc:creator>
    <dc:date>2016-05-27T12:37:58Z</dc:date>
    <item>
      <title>ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485782#M538742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: Arial;"&gt;Hi all,&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;I´m working closely with a partner on a specific customer case - and we have some issue when testing high availability - in this case - AD is down.&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;In short : &lt;/P&gt;&lt;P style="font-family: Arial;"&gt;Using the Legacy style – there was no way for the switch to see whether it was a dot1x request or a MAB. When AD is down the ISE servers are configured to do DROP on the packet so that the ISE PSN is marked dead in radius config. &lt;/P&gt;&lt;P style="font-family: Arial;"&gt;Using MAB on the same switch causes the connected ports with 802.1x clients that have been put into “CRITICAL AUTH” to reinitialize and try to reauthenticate, whichs causes a on/off/on/off/on… etc. scenario&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;We have worked on multiple solutions - and for now we are working on using C3PL to get this working.&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;A really cool thing with C3PL is - that we will be able to start MAB and dot1x at the same time - any caveats/pitfalls we are not aware of ?&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;So - I want to hear what other customers/users do in this scenario ?? &lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;Do we (Cisco) recommend using C3PL for this or ?&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;And furthermore - if anyone is using C3PL - please share config &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;Best regards&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;Tue Noergaard&lt;/P&gt;&lt;P style="font-family: Arial;"&gt;CSE - Cisco DK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 12:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485782#M538742</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-05-27T12:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485783#M538743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tue, thanks for sharing your experience. It is true that IBNS 2.0 (AKA C3PL Syntax) works wonders due to its flexibility. Aside from what you brought up it can provide CRITICAL ACL feature where switch can add/remove ACL based on AAA status, simplify interface configurations, use multiple RADIUS servers for ports and MAB/802.1X among other things. When it comes to ISE, customers can use either method on their switches based on their needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The simultaneous auth available with IBNS 2.0 should work but it hasn't been explicitly tested with ISE. One side effect of such configuration would be additional load on the servers as each endpoints connecting will have two authentications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also interested in hearing from others around unique ways using IBNS 2.0 so please feel free to post sample configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hosuk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 12:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485783#M538743</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-05-27T12:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485784#M538744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we provide any best practise advice on this subject ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer in this case needs to know if C3PL is the right way to go or not ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;br,&lt;/P&gt;&lt;P&gt;Tue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 12:37:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485784#M538744</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-05-27T12:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485785#M538745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't say it is the best practice, but one workaround you can try is to define same ISE node two times with different RADIUS ports. One using 1645 &amp;amp; 1646 and another with same IP using 1812 &amp;amp; 1813. &lt;SPAN style="font-size: 10pt;"&gt;With IBNS 2.0 you can point 802.1X to the first one and MAB to the second one and getting no response due to AD will not impact the MAB requests as it is considered separate RADIUS server from switch side.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hosuk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 12:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485785#M538745</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-05-27T12:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485786#M538747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your replies &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know of any customers actually using C3PL in production ?&lt;/P&gt;&lt;P&gt;We need to ease the customers mind that this is a "safe and/or recommend" way to follow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Tue &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 13:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485786#M538747</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-05-27T13:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485787#M538749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes many customers are already on IBNS 2.0 mainly due to CRITICAL ACL feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2016 13:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485787#M538749</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-05-27T13:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485788#M538750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the code we are working on now:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa new-model&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa group server radius ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;server-private 10.158.33.216 timeout 1 retransmit 2 key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;server-private 10.158.33.225 timeout 1 retransmit 2 key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa group server radius ISE-MAB-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;server-private 10.158.33.225 timeout 1 retransmit 2 test username ise-tester idle-time 1 key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;server-private 10.158.33.216 timeout 1 retransmit 2 test username ise-tester idle-time 1 key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa authentication dot1x DOT1X group ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa authentication dot1x MAB group ISE-MAB-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa authorization network default group ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa authorization network ISE-DOT1X-DK-TESTBED none&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa accounting update periodic 60&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa accounting identity default start-stop group ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa accounting network default start-stop group ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa accounting system default start-stop group ISE-DOT1X-DK-TESTBED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;client 10.158.33.216 server-key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;client 10.158.33.225 server-key 7 *&lt;STRONG&gt;gracefullyremoved&lt;/STRONG&gt;*&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-template webauth-global-inactive&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;inactivity-timer 3600 &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-template CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;access-group ACL-ALLOW&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan 107&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-template CRITICAL_VOICE&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;access-group ACL-ALLOW&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;voice vlan&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-template CRITICAL_AUTHD&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;access-group ACL-ALLOW&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan 107&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-template DEFAULT_CRITICAL_VOICE_TEMPLATE&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;voice vlan&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan group useraccess vlan-list 107-108&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan dot1q tag native &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan 107&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;name 107-dot1x-UA&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;vlan 108&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;name 108-dot1x-UA&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all AAA_SVR_DOWN_AUTHD_HOST&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type aaa-timeout&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match authorization-status authorized&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all AAA_SVR_DOWN_UNAUTHD_HOST&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type aaa-timeout&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match authorization-status unauthorized&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all DOT1X&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all DOT1X_FAILED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type method dot1x authoritative&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all DOT1X_NO_RESP&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type method dot1x agent-not-found&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all DOT1X_TIMEOUT&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type method dot1x method-timeout&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-none IN_CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match activated-service-template CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-any IN_CRITICAL_AUTHD&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match activated-service-template CRITICAL_AUTHD&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-any IN_CRITICAL_VLAN&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match activated-service-template CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all MAB&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-all MAB_FAILED&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match method mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match result-type method mab authoritative&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;class-map type control subscriber match-none NOT_IN_CRITICAL_VLAN&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;match activated-service-template CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;policy-map type control subscriber DOT1X&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;event session-started match-all&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 authenticate using dot1x aaa authc-list DOT1X authz-list DOT1X retries 2 retry-time 0 priority 10&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using mab aaa authc-list MAB priority 20&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;event authentication-failure match-first&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 10 class AAA_SVR_DOWN_UNAUTHD_HOST do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 activate service-template CRITICAL&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authorize&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 30 authentication-restart 28800&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 20 class AAA_SVR_DOWN_AUTHD_HOST do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 pause reauthentication&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 30 class DOT1X_NO_RESP do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 terminate dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using mab priority 20&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 40 class MAB_FAILED do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authentication-restart 60&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 50 class DOT1X_FAILED do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 terminate dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using mab aaa authc-list MAB priority 20&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 60 class always do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 terminate dot1x&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 terminate mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 30 authentication-restart 60&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;event agent-found match-all&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using dot1x retries 2 retry-time 0 priority 10&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;event aaa-available match-all&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 10 class IN_CRITICAL do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 clear-session&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 20 class IN_CRITICAL_AUTHD do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 resume reauthentication&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 30 class AAA_SVR_DOWN_AUTHD_HOST do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 resume reauthentication&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;event violation match-all&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&amp;nbsp;&amp;nbsp; 10 restrict&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;interface GigabitEthernet1/0/2&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;description End User Port VLAN 107&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt; switchport access vlan 107&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;switchport mode access&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;switchport nonegotiate&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;ip access-group ACL-ALLOW in&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;logging event link-status&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;authentication periodic&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;authentication timer reauthenticate server&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;access-session port-control auto&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;mab&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;no snmp trap link-status&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;dot1x pae authenticator&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;dot1x timeout tx-period 10&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;storm-control broadcast level 70.00&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;storm-control multicast level 70.00&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;storm-control action trap&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;no cdp enable&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;spanning-tree portfast&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;service-policy type control subscriber DOT1X&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;ip access-list extended ACL-ALLOW&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;permit ip any any&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;ip access-list extended REDIRECT&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;deny&amp;nbsp;&amp;nbsp; ip any host 10.158.33.216&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;deny&amp;nbsp;&amp;nbsp; ip any host 10.158.33.225&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;permit ip any any&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;!&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;radius-server dead-criteria time 30 tries 3&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Comments ?&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;If anyone will share their code - I´d love to see it.&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;/Tue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2016 09:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485788#M538750</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-06-01T09:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485789#M538751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tue and Hosuk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm actually trying out the same c3pl code based on the document for 3850 universal config (that Hosuk wrote) integrated with ISE 2.1.&lt;/P&gt;&lt;P&gt;For the moment I do see both auth's being triggered at the same time and it looks like it works fine, but ISE behaviour for now is to generate an alarm for the NAD misconfiguration as having too many accounting packets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to admit that having both auth methods simultaneously confuses me in a few aspects:&lt;/P&gt;&lt;P&gt;- 802.1X takes longer to authenticate than mab (more transactions)&lt;/P&gt;&lt;P&gt;- if mab succeeds, an accounting start will be sent.&lt;/P&gt;&lt;P&gt;- but then 802.1X also succeeds (it just took longer) - which will also trigger an accounting start&lt;/P&gt;&lt;P&gt;- will the switch drop the mab session then?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also like to have best practice reference guide for C3PL covering multiple cases - 802.1X and MAB for endpoints (with ISE CWA); 802.1X, MAB and webauth; only MAB, etc... Does any of this exist? &lt;/P&gt;&lt;P&gt;If the use cases reference guide is not possible, then a more thorough explanation on how to design a C3PL policy covering multiple cases&amp;nbsp; - which events to look for, which classes to match, which actions to take and their impact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gustavo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2016 18:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485789#M538751</guid>
      <dc:creator>Gustavo Novais</dc:creator>
      <dc:date>2016-07-08T18:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485790#M538752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just found out that actually there are a lot of templates already provided with the Auto-identity feature (&lt;A class="loading" href="http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/auto_id.pdf" title="http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/auto_id.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/auto_id.pdf&lt;/A&gt;), besides a good lab guide in cisco live (LTRSEC-2017-LG).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Might help anyone trying to dive into C3PL for identity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gustavo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2016 18:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485790#M538752</guid>
      <dc:creator>Gustavo Novais</dc:creator>
      <dc:date>2016-07-08T18:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - C3PL or legacy style ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485791#M538753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did someone has a solution for the AD availability. With the automatic-test the switch can send a username and the dead-criteria is working. However like Tue said, there is an on/off/on/off situation. &lt;/P&gt;&lt;P&gt;Is it possible that Cisco will provide a fix for this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;BR /&gt;Sander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Mar 2017 15:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-c3pl-or-legacy-style/m-p/3485791#M538753</guid>
      <dc:creator>S M85</dc:creator>
      <dc:date>2017-03-10T15:22:13Z</dc:date>
    </item>
  </channel>
</rss>

