<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using blank or null value in the condition for authorization policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3724426#M542866</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were trying to create a condition to match an AD attribute to a null/blank value. We tried few regex expression values like null, =null, ^$ in the value field, but still we were not able to match the authorization condition. the condition&amp;nbsp;algorithm goes like this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If AD attribute = "null value"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then&lt;/P&gt;
&lt;P&gt;Auhorization result: Deny Access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise which value or which approach would work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aravind.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:50:34 GMT</pubDate>
    <dc:creator>aravikumar</dc:creator>
    <dc:date>2019-03-11T08:50:34Z</dc:date>
    <item>
      <title>Using blank or null value in the condition for authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3724426#M542866</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were trying to create a condition to match an AD attribute to a null/blank value. We tried few regex expression values like null, =null, ^$ in the value field, but still we were not able to match the authorization condition. the condition&amp;nbsp;algorithm goes like this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If AD attribute = "null value"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then&lt;/P&gt;
&lt;P&gt;Auhorization result: Deny Access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise which value or which approach would work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aravind.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3724426#M542866</guid>
      <dc:creator>aravikumar</dc:creator>
      <dc:date>2019-03-11T08:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Using blank or null value in the condition for authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3724495#M542868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Why not specify rules that match conditions/attributes above a default rule which denies access? This would deny the null/blank values which would not be match in the more specific rules above.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 18:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3724495#M542868</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-12T18:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using blank or null value in the condition for authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3728896#M542870</link>
      <description>&lt;P&gt;There is a bug on ISE that causes the endpoint profile/endpoint group to be modified from a valid value&amp;nbsp;into: blank/unknown/profiled after successful authentication. Instead of using&amp;nbsp;the AUTHZ Policies, I was playing with the PURGE process of ISE trying to delete those blank entries from the Endpoint DB, no luck. I am working with TAC on this issue (there is another way to do this but requires root access). So looks likes the same applies to AUTHZ Policies. I wanted to remove invalid&amp;nbsp;entries from the Endpoint DB.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 20:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3728896#M542870</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-10-19T20:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using blank or null value in the condition for authorization policy</title>
      <link>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3729292#M542872</link>
      <description>&lt;P&gt;With ISE 2.3+, we may use "is not" and the following seems to work for me.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2018-10-21 at 5.02.39 AM.png" style="width: 340px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20817i1EF28523EC2F3E86/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2018-10-21 at 5.02.39 AM.png" alt="Screen Shot 2018-10-21 at 5.02.39 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 12:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-blank-or-null-value-in-the-condition-for-authorization/m-p/3729292#M542872</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-21T12:03:53Z</dc:date>
    </item>
  </channel>
</rss>

