<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network Access:ISE Host Name Condition in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532096#M540920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai, I received the debugs logs and I could see it was picking up the correct Authorization Policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then went back to the RADIUS live logs and I could see again it was picking up the correct Authorization Policy.&lt;/P&gt;&lt;P&gt;So it is working , perhaps I was mistaking it for Authorization Profile name which is same as the old/duplicate rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm I am using an attirbute of Network Access: ISE Hostname Equals &amp;lt;ISE HOSTNAME&amp;nbsp; CASE SENSITVE&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Dec 2016 11:06:09 GMT</pubDate>
    <dc:creator>joshhunter</dc:creator>
    <dc:date>2016-12-12T11:06:09Z</dc:date>
    <item>
      <title>Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532090#M540914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm struggling to get the "&lt;SPAN style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; background-color: #f9f9f9;"&gt;Network Access:ISE Host Name EQUALS &amp;lt;ISEHOSTNAME&amp;gt;"&amp;nbsp; condition to work fur Guest Portal Redundancy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand it is case sensitive and I have tried Match and Contain but still it does not match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Read through this document, &lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117620-configure-ISE-00.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117620-configure-ISE-00.html"&gt;ISE with Static Redirect for Isolated Guest Networks Configuration Example - Cisco &lt;/A&gt;&lt;/P&gt;&lt;P&gt;with no joy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2016 14:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532090#M540914</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-11-22T14:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532091#M540915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you try “Starts With” and see if it matches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532091#M540915</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2016-11-22T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532092#M540916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim, I tried this too and no joy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is only a 2 node deployment and is definitely the correct node as I can see it in the Live Authentication details tab for client as Policy Server. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532092#M540916</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-11-22T15:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532093#M540917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which version of ISE are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2016 16:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532093#M540917</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2016-11-22T16:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532094#M540918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very latest 2.1 Patch 1&amp;nbsp; (2.1.0.474) Patch 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2016 16:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532094#M540918</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-11-22T16:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532095#M540919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you test it working with an earlier ISE release?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may DEBUG on epm-pdp, epm-pip, and nsf-session, and then check ise-psc.log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2016 05:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532095#M540919</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-12-05T05:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532096#M540920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai, I received the debugs logs and I could see it was picking up the correct Authorization Policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then went back to the RADIUS live logs and I could see again it was picking up the correct Authorization Policy.&lt;/P&gt;&lt;P&gt;So it is working , perhaps I was mistaking it for Authorization Profile name which is same as the old/duplicate rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm I am using an attirbute of Network Access: ISE Hostname Equals &amp;lt;ISE HOSTNAME&amp;nbsp; CASE SENSITVE&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Dec 2016 11:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532096#M540920</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2016-12-12T11:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532097#M540921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same problem, the condition ISE Hostname Equals &amp;lt;ISE HOSTNAME&amp;nbsp; CASE SENSITVE&amp;gt; works for only one ISE but not for the other one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't work with ISE 2.1 patch 2 neither.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 17:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532097#M540921</guid>
      <dc:creator>Thibault BRISSE</dc:creator>
      <dc:date>2017-02-02T17:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532098#M540922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a TAC case if the setup is for production or customers'. In case it's your lab, please share debug log snippets and more details on &lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;works for only one ISE but not for the other one.&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 19:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532098#M540922</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-02-02T19:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Network Access:ISE Host Name Condition</title>
      <link>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532099#M540923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thiabault, this actually worked fine for me in the end.&lt;/P&gt;&lt;P&gt;I had reviewed the RADIUS Live Logs incorrectly, it was actually hitting the correct Authorization Rule for ISE2, I was reading the logs wrongly and mistaking the Authentication Rule as being the Authz rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is for Guest WLC make sure you specific the correct PSN (RADIUS) server configured on your Guest Wireless SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also use the details tab under via RADIUS Live Logs for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 19:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-access-ise-host-name-condition/m-p/3532099#M540923</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2017-02-02T19:05:21Z</dc:date>
    </item>
  </channel>
</rss>

