<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE with Meraki using Wireless 802.1x - Radius:Service-Type = Framed not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3184564#M555605</link>
    <description>&lt;P&gt;The firmware of the APs in the Meraki Dashboard claims to be "Up to date".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using ISE to authenticate Wireless 802.1x corporate users against the AD using PEAP-MSCHAPv2. Using the default Wireless 802.1x compund condition (which uses Radius:Service-Type = Framed) simply does not work. The rule is skipped and the request ends up being catched by the default authentication rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new condition with only Radius:NAS-Port-Type - Wireless - IEEE 802.11 and now that rule catches the request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the same thing happens with the Authorization rule. Meraki seems to not understand Radius:Service-Type and the rule that uses it gets skipped. If I get rid of that attribute and try to match on an AD group, it also won't match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to create different authroization rules on ISE based on different AD groups if my APs are Meraki?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alfonso&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:34:12 GMT</pubDate>
    <dc:creator>Alfonso Lopez</dc:creator>
    <dc:date>2020-02-21T18:34:12Z</dc:date>
    <item>
      <title>ISE with Meraki using Wireless 802.1x - Radius:Service-Type = Framed not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3184564#M555605</link>
      <description>&lt;P&gt;The firmware of the APs in the Meraki Dashboard claims to be "Up to date".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using ISE to authenticate Wireless 802.1x corporate users against the AD using PEAP-MSCHAPv2. Using the default Wireless 802.1x compund condition (which uses Radius:Service-Type = Framed) simply does not work. The rule is skipped and the request ends up being catched by the default authentication rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new condition with only Radius:NAS-Port-Type - Wireless - IEEE 802.11 and now that rule catches the request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the same thing happens with the Authorization rule. Meraki seems to not understand Radius:Service-Type and the rule that uses it gets skipped. If I get rid of that attribute and try to match on an AD group, it also won't match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to create different authroization rules on ISE based on different AD groups if my APs are Meraki?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alfonso&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3184564#M555605</guid>
      <dc:creator>Alfonso Lopez</dc:creator>
      <dc:date>2020-02-21T18:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with Meraki using Wireless 802.1x - Radius:Service-Type = Framed not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3184937#M555606</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;I didn't do dot1x implementation with Meraki devices. &lt;BR /&gt;However i can help you on ise. &lt;BR /&gt;First of all, can you take a tcpdump capture on ise while authenticating through a Meraki devices? &lt;BR /&gt;&lt;BR /&gt;Can you share your ise configuration as will to take a look?&lt;BR /&gt;</description>
      <pubDate>Sat, 16 Sep 2017 03:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3184937#M555606</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-09-16T03:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with Meraki using Wireless 802.1x - Radius:Service-Type = Framed not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3188850#M555607</link>
      <description>&lt;P&gt;Well, I solved it by simply installing patch 1 on our ISE 2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's now matching a rule that uses Service-Type = Framed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authorization condition has 4 attributes:&lt;/P&gt;&lt;P&gt;- Nas Port Type = Wireless IEEE 802.11&lt;/P&gt;&lt;P&gt;- Service Type = Framed&lt;/P&gt;&lt;P&gt;- External Group = Domain Users&lt;/P&gt;&lt;P&gt;- Networkaccess = Userauthenticated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I hope this helps someone else facing the same issue. The solution was simply to install patch 1...&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 08:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-meraki-using-wireless-802-1x-radius-service-type-framed/m-p/3188850#M555607</guid>
      <dc:creator>Alfonso Lopez</dc:creator>
      <dc:date>2017-09-25T08:28:08Z</dc:date>
    </item>
  </channel>
</rss>

