<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I have  the same pb in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4065431#M559582</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I tried with Cisco ISE 2.6 to add&amp;nbsp; &amp;nbsp;a tacacs authorization&amp;nbsp; rule in "monitor" mode.&lt;/P&gt;&lt;P&gt;I placed this rule at the top.&lt;/P&gt;&lt;P&gt;But I never see the&amp;nbsp; attribute "&lt;SPAN&gt;RadiusAuthorizationPolicyMatchedMonitorRules" in the live logs&amp;nbsp; AuthZ detail&amp;nbsp; (under "other attributes").&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alltthough, I know that rule matches , because , when I change the status (from monitor to Enable), this rule matches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michel Misonne&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2020 12:50:01 GMT</pubDate>
    <dc:creator>mmisonne</dc:creator>
    <dc:date>2020-04-14T12:50:01Z</dc:date>
    <item>
      <title>AuthZ Policy “Monitor Only” mode</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662585#M74516</link>
      <description>&lt;P&gt;I have a question about the AuthZ Policy “Monitor Only” or "Audit" mode.&amp;nbsp; I want to test a new AuthZ policy by using “Monitor Only” mode, but I am not seeing any indication that my Test device is hitting the rule while in Monitor only mode… It ends up hitting our last default rule which is currently permit any.&amp;nbsp; If I actually enable the rule, I can see the device hitting the rule and getting denied in the Authentication log window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I know the rule works, but I want to only &lt;U&gt;monitor &lt;/U&gt;the rule for now to see what would get denied, so that we can assess how we want to handle auth for said devices.&amp;nbsp; According some info I found, I should be seeing an indication in the Auth log window that a rule was matched, if it is Monitor only mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently running ISE &lt;B&gt;1.3.0.876.&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662585#M74516</guid>
      <dc:creator>cjkaufman@dmgov.org</dc:creator>
      <dc:date>2019-03-11T05:27:00Z</dc:date>
    </item>
    <item>
      <title>I have had the same</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662586#M74517</link>
      <description>&lt;P&gt;I have had the same experience. &amp;nbsp;If you look at the AuthZ details for the connection, you will see under Other Attributes a&amp;nbsp;special attribute returned named "RadiusAuthorizationPolicyMatchedMonitorRules," but as far as I know there is no way to run a report on it. Maybe someone else has a suggestion on it.&lt;/P&gt;&lt;P&gt;What I do as a workaround is create a rule matching the conditions and create a special Authorization Profile for the rule that just has ACCESS_ACCEPT (not to break any traffic), then run a RADIUS Authentication report matching that Authorization Profile.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 22:29:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662586#M74517</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2015-02-12T22:29:18Z</dc:date>
    </item>
    <item>
      <title>Thanks.   I see that in the</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662587#M74519</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&amp;nbsp; I see that in the session details now.&amp;nbsp; That is quite a cumbersome way to use the Audit option.&amp;nbsp; It would be nice if they could highlight the session a difference color to show that it matched the Audited rule.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 20:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/2662587#M74519</guid>
      <dc:creator>cjkaufman@dmgov.org</dc:creator>
      <dc:date>2015-02-13T20:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: I have  the same pb</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4065431#M559582</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I tried with Cisco ISE 2.6 to add&amp;nbsp; &amp;nbsp;a tacacs authorization&amp;nbsp; rule in "monitor" mode.&lt;/P&gt;&lt;P&gt;I placed this rule at the top.&lt;/P&gt;&lt;P&gt;But I never see the&amp;nbsp; attribute "&lt;SPAN&gt;RadiusAuthorizationPolicyMatchedMonitorRules" in the live logs&amp;nbsp; AuthZ detail&amp;nbsp; (under "other attributes").&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alltthough, I know that rule matches , because , when I change the status (from monitor to Enable), this rule matches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michel Misonne&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4065431#M559582</guid>
      <dc:creator>mmisonne</dc:creator>
      <dc:date>2020-04-14T12:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: I have  the same pb</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4065928#M559609</link>
      <description>&lt;P&gt;A TACACS+ session is never going to match the RADIUS attribute "RadiusAuthorizationPolicyMatchedMonitorRules"&lt;/P&gt;
&lt;P&gt;I did some testing with a Device Admin AuthZ Policy rule set to Monitor status and do not find any attributes in either the Authentication or Authorization detailed reports that indicate a matched monitor rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unlike RADIUS that combines Authentication and Authorization, TACACS+ separates those two functions. I suspect the ability to set a Device Admin AuthZ Policy rule to Monitor status was never a fully realised feature. I even set the 'runtime-AAA' log to debug level and checked the 'ise-psc.log' and 'prrt-server.log' files, but did not see any indication of my Monitor rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect this is something that maybe never made it into the design spec for the ISE TACACS+ feature, so it's probably working as designed. If you would like to request and enhancement around this, see the following post.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-submit-an-ise-feature-or-enhancement-request/ta-p/3772439" target="_self"&gt;How to Submit an ISE Feature or Enhancement Request&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 23:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4065928#M559609</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-14T23:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: I have  the same pb</title>
      <link>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4066136#M559629</link>
      <description>&lt;P&gt;You are right !&lt;BR /&gt;I tried the same test (Admin access on a vWLC) using Radius, not Tacacs, and I can now see the attribute "RadiusAuthorizationPolicyMatchedMonitorRule" , when the monitoring rule matches.&lt;BR /&gt;&lt;BR /&gt;Michel Misonne&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 06:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authz-policy-monitor-only-mode/m-p/4066136#M559629</guid>
      <dc:creator>mmisonne</dc:creator>
      <dc:date>2020-04-15T06:59:25Z</dc:date>
    </item>
  </channel>
</rss>

