<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Push two authorization profiles in one authorization policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799839#M542688</link>
    <description>&lt;P&gt;Well, that makes sense...&lt;/P&gt;
&lt;P&gt;Thank you for all the inputs...&lt;/P&gt;</description>
    <pubDate>Tue, 12 Feb 2019 07:47:17 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2019-02-12T07:47:17Z</dc:date>
    <item>
      <title>Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797516#M542681</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Hello Experts,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;I am running &lt;/FONT&gt;ISE&lt;FONT face="helvetica" size="2"&gt; 2.4 with patch 4.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;In the authorization policy is it possible to push two authorization profiles?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;If yes, then which ones will take the precedence?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;Or is this something that the design of ISE does not allow?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Any pointers or documentation to achieve this?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797516#M542681</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-03-11T08:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797560#M542682</link>
      <description>No you can't combine two profiles in one rule. With the profile you can&lt;BR /&gt;combination of ands and ors nested&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Feb 2019 09:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797560#M542682</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-08T09:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797925#M542683</link>
      <description>I think you might get more helpful advise if you were to try and explain why you think you need two authorization results.  To clarify the terms, I'm assuming authorization results because that's what ise would send back to the switch/wlc.  As indicated in the previous post, it's not possible, but there are usually ways to accomplish most rule requirements.</description>
      <pubDate>Fri, 08 Feb 2019 16:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3797925#M542683</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-08T16:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3798538#M542684</link>
      <description>&lt;P&gt;If the matched authz policy rule has multiple profiles. They are combined in such way that distinct attributes will all apply and the first values of the same attributes will apply.&lt;/P&gt;
&lt;P&gt;For example, the following rule has three authz profiles:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;dACL PermitALL -- with the attribute for DACL -- PERMIT_ALL&lt;/LI&gt;
&lt;LI&gt;vlan 100 -- with the common task VLAN set to 100&lt;/LI&gt;
&lt;LI&gt;vlan 101 -- with the common task VLAN set to 101&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-02-09 at 3.36.43 PM.png" style="width: 793px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29771i65C22E7CFDE563A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-02-09 at 3.36.43 PM.png" alt="Screen Shot 2019-02-09 at 3.36.43 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As the DACL is unique and VLAN assignments are duplicated, the resulting permissions would have DACL PERMIT_ALL and the first VLAN assignment, which set to 100.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Feb 2019 23:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3798538#M542684</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-09T23:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799058#M542685</link>
      <description>&lt;P&gt;I was thinking about a use case, where the WLC has ACL has a limitation of 64 lines in single ACL. So, what if I create multiple dACL and push them via authorization profiles, thus increasing the overall capacity.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 10:27:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799058#M542685</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-02-11T10:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799142#M542686</link>
      <description>Hi,&lt;BR /&gt;I know this is not directly related to your question but I don't think you can push DACL to WLC, you can create ACL locally on the WLC and call it by its name in the Authorization profile via "airspace ACL" option.</description>
      <pubDate>Mon, 11 Feb 2019 12:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799142#M542686</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-11T12:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799260#M542687</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/529249" target="_blank"&gt;bern81&lt;/A&gt;&amp;nbsp;is correct that WLC not using DACL. If needing many ACEs, then you should consider another solution (e.g. ASA) to perform the enforcement.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 14:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799260#M542687</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-11T14:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Push two authorization profiles in one authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799839#M542688</link>
      <description>&lt;P&gt;Well, that makes sense...&lt;/P&gt;
&lt;P&gt;Thank you for all the inputs...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 07:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/push-two-authorization-profiles-in-one-authorization-policy/m-p/3799839#M542688</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-02-12T07:47:17Z</dc:date>
    </item>
  </channel>
</rss>

