<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Customize Compound condition in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215247#M551348</link>
    <description>Policy &amp;gt; policy elements &amp;gt; conditions.  You can select authorization&lt;BR /&gt;conditions and compound&lt;BR /&gt;</description>
    <pubDate>Sun, 12 Nov 2017 17:22:58 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2017-11-12T17:22:58Z</dc:date>
    <item>
      <title>Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215235#M551347</link>
      <description>&lt;P&gt;Hello guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where the Tab in ISE 2.1&amp;nbsp; so that i can&amp;nbsp; i create new "&lt;STRONG&gt;Compound condition&lt;/STRONG&gt;" to make a group of condition like &lt;STRONG&gt;wired_mab&lt;/STRONG&gt; and &lt;STRONG&gt;wireless_mab&lt;/STRONG&gt; in new customized one named &lt;STRONG&gt;MAB&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215235#M551347</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2020-02-21T18:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215247#M551348</link>
      <description>Policy &amp;gt; policy elements &amp;gt; conditions.  You can select authorization&lt;BR /&gt;conditions and compound&lt;BR /&gt;</description>
      <pubDate>Sun, 12 Nov 2017 17:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215247#M551348</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-11-12T17:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215248#M551349</link>
      <description>&lt;P&gt;That would be under Policy -&amp;gt; Policy elements -&amp;gt; Conditions -&amp;gt; Authentication -&amp;gt; Compound conditions&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 17:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215248#M551349</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-11-12T17:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215259#M551350</link>
      <description>&lt;P&gt;Hello guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for answering my thread&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't find it , how to create my customization Compound name it MAB and add default builtin condition&amp;nbsp; &lt;STRONG&gt;Wired_MAB&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Wireless MAB&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 18:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215259#M551350</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2017-11-12T18:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215276#M551351</link>
      <description>&lt;P&gt;As we mentioned before compound conditions can be defined under Policy -&amp;gt; Policy elements -&amp;gt; Conditions -&amp;gt; Authentication -&amp;gt; Compound conditions.&lt;BR /&gt;Compound conditions can contain multiple Simple conditions or custom attribute/value pairs, but they can't contain other Compound conditions within them. Both Wired_MAB &amp;amp; Wireless_MAB are compound conditions themselves.&lt;BR /&gt;For example, Cisco Wireless_MAB compound condition contains the following:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Radius:NAS-Port-Type = Wireless - IEEE 802.11 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Radius:Service-Type = Call Check&lt;/FONT&gt;&lt;BR /&gt;So you would first need to create a bunch of simple conditions and then add them to your Compound condition.&lt;/P&gt;
&lt;P&gt;Where do you want to use your new Compound condition? Are you unable to use OR operator to check for both&amp;nbsp;Wired_MAB OR Wireless MAB?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 20:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215276#M551351</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-11-12T20:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215436#M551352</link>
      <description>&lt;P&gt;Hello&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt; &lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/282818" target="_self"&gt;&lt;SPAN class=""&gt;agrissimanis&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;very informative answer from you , let me learn from you&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;for &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;a) VPN Rule , what would be the conditions for both Authentication and Authorization policy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;b) for normal AAA test from device to cisco ISE , what would be the rule , as i have the default Authentication and authorization policy with &lt;STRONG&gt;DenyAccess&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Bronze lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;thanks &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 07:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215436#M551352</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2017-11-13T07:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Customize Compound condition</title>
      <link>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215557#M551353</link>
      <description>&lt;P&gt;For VPN you could do something like this:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Radius:NAS-Port-Type EQUALS Virtual AND&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;DEVICE:Device Type EQUALS Device Type#All Device Types#ASA Firewall&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Authorization could be anything you want, for example to match on AD group membership you would do &lt;FONT face="courier new,courier"&gt;MyDomain:ExternalGroups EQUALS MyDomain/Users/VPN User Group&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For AAA test the condition could be this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;Radius:NAS-Port-Type EQUALS&amp;nbsp;Async&lt;/FONT&gt; or maybe &lt;FONT face="courier new,courier"&gt;Radius:Service-Type&amp;nbsp;EQUALS Login&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;These conditions depend on what other policies you have configured and the ordering of the rules. The test requests from switches can be denied, it is not a problem. The switch just needs to see if there is a live RADIUS server, in most scenarios&amp;nbsp;it doesn't matter if the authentication passes or fails.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 12:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/customize-compound-condition/m-p/3215557#M551353</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-11-13T12:00:54Z</dc:date>
    </item>
  </channel>
</rss>

