<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE MAB Authentication problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4189454#M564019</link>
    <description>&lt;P&gt;There is not enough information being provided to help. See &lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank" rel="noopener"&gt;How to Ask The Community for Help&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the step data, the session is hitting some AuthZ rule that is returning an ACCESS_ACCEPT. You'll need to either provide more detail on your full Authentication/Authorization Policies, Authorization Profiles involved, etc. or open a case with TAC to investigate further.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 21:48:16 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-11-26T21:48:16Z</dc:date>
    <item>
      <title>Cisco ISE MAB Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188735#M563986</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Good day, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i have a problem where I can't get any further.&lt;BR /&gt;Unknown hosts that authenticate themselves via MAB are automatically moved to the "unknown" group.&lt;BR /&gt;This group was not created by me. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The client is then allowed into the network.&lt;BR /&gt;Ise lets every client into the network as soon as it lands in the unknown group.&lt;BR /&gt;Creating a policy which should block the unknown group unfortunately didn't help either.&lt;BR /&gt;&lt;BR /&gt;Could you please provide me some tips on my problem ?&lt;BR /&gt;If you need more detailed informations please let me know.&lt;BR /&gt;&lt;BR /&gt;Best regards and thank you in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188735#M563986</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2020-11-25T14:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE MAB Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188799#M563989</link>
      <description>&lt;P&gt;FYSA:&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;An unknown profile is the default system profiling policy that is assigned to an endpoint, where an attribute or a set of attributes collected for that endpoint do not match with existing profiles in Cisco ISE.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;An Unknown profile is assigned in the following scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;When an endpoint is dynamically discovered in Cisco ISE, and there is no matching endpoint profiling policy for that endpoint, it is assigned to the unknown profile.&lt;/LI&gt;
&lt;LI class="pBu1_Bullet1"&gt;When an endpoint is statically added in Cisco ISE, and there is no matching endpoint profiling policy for a statically added endpoint, it is assigned to the unknown profile.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Can you share your mab authz policies? Is your wish to support both mab and dot1x? Are you using any sorts of custom profiling? Do you reference identity groups as a condition in your authz conditions?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 16:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188799#M563989</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-11-25T16:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE MAB Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188839#M563990</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you in advance for your feedback. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We use both 802.1x and mab authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Even if I create a policy "identity group - unknown - deny access" it still gets authenticated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I attached two pictures.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;edit*&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Profiling is not enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 17:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4188839#M563990</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2020-11-27T17:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE MAB Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4189332#M564016</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I've attached another picture. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is no policy that extends access for the "unknown" identity group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 17:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4189332#M564016</guid>
      <dc:creator>andreasalberti</dc:creator>
      <dc:date>2020-11-27T17:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE MAB Authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4189454#M564019</link>
      <description>&lt;P&gt;There is not enough information being provided to help. See &lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank" rel="noopener"&gt;How to Ask The Community for Help&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the step data, the session is hitting some AuthZ rule that is returning an ACCESS_ACCEPT. You'll need to either provide more detail on your full Authentication/Authorization Policies, Authorization Profiles involved, etc. or open a case with TAC to investigate further.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 21:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-mab-authentication-problems/m-p/4189454#M564019</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-11-26T21:48:16Z</dc:date>
    </item>
  </channel>
</rss>

