<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070354#M559784</link>
    <description>&lt;P&gt;Thank you for your quick reply ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greg you are right there is no such attribute in RFC .&lt;/P&gt;&lt;P&gt;I saw it in ISE in Authentication details (other attributes)&amp;nbsp; that's why i am asking.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="attributes.jpg" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72381i7656F5984F6C685F/image-size/small?v=v2&amp;amp;px=200" role="button" title="attributes.jpg" alt="attributes.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create a policy for requests coming from the &lt;STRONG&gt;same device&lt;/STRONG&gt; , (an ASA) with two authentication methods (primary,secondary).&lt;/P&gt;&lt;P&gt;The primary authentication&amp;nbsp; should match the first policy and the secondary the other .&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2020 07:21:19 GMT</pubDate>
    <dc:creator>Spyros Kasapis</dc:creator>
    <dc:date>2020-04-21T07:21:19Z</dc:date>
    <item>
      <title>ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070045#M559778</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a way to create a policy based on DestinationPort&amp;nbsp; radius attribute ? (1812 or 1645)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spyros&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 20:09:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070045#M559778</guid>
      <dc:creator>Spyros Kasapis</dc:creator>
      <dc:date>2020-04-20T20:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070166#M559781</link>
      <description>Take a look at this link:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-network-access-attributes/ta-p/3616253#toc-hId-1189009796" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-network-access-attributes/ta-p/3616253#toc-hId-1189009796&lt;/A&gt;&lt;BR /&gt;You may be able to utilize the NAS-Port attribute to meet your needs.  HTH!&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Apr 2020 00:16:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070166#M559781</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-04-21T00:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070219#M559782</link>
      <description>&lt;P&gt;I don't believe it is possible to create policy based on that value. There is no such attribute in the RADIUS &lt;A href="https://tools.ietf.org/html/rfc2865" target="_blank" rel="noopener"&gt;RFC2865&lt;/A&gt; and there are no Cisco-specific attributes that include this info in the supported &lt;A href="https://community.cisco.com/t5/security-documents/ise-network-access-attributes/ta-p/3616253#toc-hId--1762504210" target="_blank" rel="noopener"&gt;ISE Network Access Attributes&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If you're wanting to create different policies based upon the Network Device initiating the RADIUS request, the common approach is to create Network Device Groups and use those as conditions in your policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 01:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070219#M559782</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-21T01:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070354#M559784</link>
      <description>&lt;P&gt;Thank you for your quick reply ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greg you are right there is no such attribute in RFC .&lt;/P&gt;&lt;P&gt;I saw it in ISE in Authentication details (other attributes)&amp;nbsp; that's why i am asking.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="attributes.jpg" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72381i7656F5984F6C685F/image-size/small?v=v2&amp;amp;px=200" role="button" title="attributes.jpg" alt="attributes.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create a policy for requests coming from the &lt;STRONG&gt;same device&lt;/STRONG&gt; , (an ASA) with two authentication methods (primary,secondary).&lt;/P&gt;&lt;P&gt;The primary authentication&amp;nbsp; should match the first policy and the secondary the other .&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 07:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070354#M559784</guid>
      <dc:creator>Spyros Kasapis</dc:creator>
      <dc:date>2020-04-21T07:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070560#M559792</link>
      <description>&lt;P&gt;We found a solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In ASA we make the requests from different ip addresses (interfaces).&lt;/P&gt;&lt;P&gt;In ISE the policy matches with the NAS IPv4 Address which is different .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 13:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy/m-p/4070560#M559792</guid>
      <dc:creator>Spyros Kasapis</dc:creator>
      <dc:date>2020-04-21T13:14:21Z</dc:date>
    </item>
  </channel>
</rss>

