<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlapping NAD IPs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4294889#M565615</link>
    <description>&lt;P&gt;&lt;BR /&gt;OK. I think concept is as follow.&lt;/P&gt;&lt;P&gt;Lets assume there are 4 NAD objects as follow:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 937px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104771iF90ACE2AC20869EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;TEST.IP1 = 80.80.80.0/24 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP2 = 80.80.80.30/32 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP3 = 80.80.80.16/32 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP4 = 80.80.80.8-9/32 (Type IP range)&lt;/P&gt;&lt;P&gt;Matching order will be:&lt;/P&gt;&lt;P&gt;1. TEST.IP2 and TEST.IP3 becuase the longest match&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. TEST.IP1 becuase IP address type has higher preference over IP range object&lt;/P&gt;&lt;P&gt;3. TEST.IP4 becuase IP range object has lower preference than IP address object&lt;/P&gt;&lt;P&gt;It may be miisleading becuase defining range 80.80.80.8-9/32 administrator expect that it will matched over entire subnet 80.80.80.0/24 but becuase IP range object has lower preference than IP address type its exactly oposite.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Feb 2021 09:46:48 GMT</pubDate>
    <dc:creator>stcnetteam</dc:creator>
    <dc:date>2021-02-21T09:46:48Z</dc:date>
    <item>
      <title>Overlapping NAD IPs</title>
      <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4289406#M565397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have noted recently that ISE allows to create two overlapped NAD objects in terms of IP. Does anyone have an idea how the matching process looks like then? In our company /24 object had preference causing issues. I am wondering if this is anywhere documented.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See example below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="download.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104112iCD3D3B39E5134DC1/image-size/large?v=v2&amp;amp;px=999" role="button" title="download.png" alt="download.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 13:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4289406#M565397</guid>
      <dc:creator>stcnetteam</dc:creator>
      <dc:date>2021-02-10T13:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping NAD IPs</title>
      <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4289544#M565402</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;So the more specific NAD will take precedence when the request comes in.&lt;BR /&gt;NADs with no specific IPs in ISE DB will match the subnet NAD.&lt;BR /&gt;&lt;BR /&gt;Quoted:&lt;BR /&gt;&lt;BR /&gt;*Note *If device A has an IP address range defined, you can configure&lt;BR /&gt;another device B with an individual address from the range that is defined&lt;BR /&gt;in device A.&lt;BR /&gt;------------------------------&lt;BR /&gt;&lt;BR /&gt;When Cisco ISE receives a RADIUS request and tries to match the request&lt;BR /&gt;against a network device, it does the following:&lt;BR /&gt;&lt;BR /&gt;*a. *It looks for a specific IP address that matches the one in the request.&lt;BR /&gt;&lt;BR /&gt;*b. *It looks up the ranges to see if the IP address in the request falls&lt;BR /&gt;within the range that is specified.&lt;BR /&gt;&lt;BR /&gt;*c. *If both of these fail, it uses the default device definition (if&lt;BR /&gt;defined) to process the request.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_network_devices.html" target="_blank"&gt;https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_network_devices.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Feb 2021 17:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4289544#M565402</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-02-10T17:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping NAD IPs</title>
      <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4294889#M565615</link>
      <description>&lt;P&gt;&lt;BR /&gt;OK. I think concept is as follow.&lt;/P&gt;&lt;P&gt;Lets assume there are 4 NAD objects as follow:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 937px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104771iF90ACE2AC20869EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;TEST.IP1 = 80.80.80.0/24 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP2 = 80.80.80.30/32 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP3 = 80.80.80.16/32 (Type IP address)&lt;/P&gt;&lt;P&gt;TEST.IP4 = 80.80.80.8-9/32 (Type IP range)&lt;/P&gt;&lt;P&gt;Matching order will be:&lt;/P&gt;&lt;P&gt;1. TEST.IP2 and TEST.IP3 becuase the longest match&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. TEST.IP1 becuase IP address type has higher preference over IP range object&lt;/P&gt;&lt;P&gt;3. TEST.IP4 becuase IP range object has lower preference than IP address object&lt;/P&gt;&lt;P&gt;It may be miisleading becuase defining range 80.80.80.8-9/32 administrator expect that it will matched over entire subnet 80.80.80.0/24 but becuase IP range object has lower preference than IP address type its exactly oposite.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 09:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4294889#M565615</guid>
      <dc:creator>stcnetteam</dc:creator>
      <dc:date>2021-02-21T09:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping NAD IPs</title>
      <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4295077#M565621</link>
      <description>&lt;P&gt;I'm curious if you tested that and confirmed the behavior of longest match?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 04:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4295077#M565621</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-02-22T04:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping NAD IPs</title>
      <link>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4295131#M565626</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually our problem started when we had "IP range" object containing two IPs "&lt;SPAN&gt;80.80.80.8-9/32". It had been never matched despite the there were only one overlapped "80.80.80.0/24" IP address object. Then i asked this question why longer matches didint happen between "IP range" and "IP address". ISE documentation explains that type "IP address" has always higher preference over "IP range". Thats why my test provides results exacly as follow:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Compare overlapped "IP address" type objects - the one with /32 wins.&lt;/LI&gt;&lt;LI&gt;If no match then try match "IP range" object"&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;As i said it may be sometimes missleading&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 07:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/overlapping-nad-ips/m-p/4295131#M565626</guid>
      <dc:creator>stcnetteam</dc:creator>
      <dc:date>2021-02-22T07:29:43Z</dc:date>
    </item>
  </channel>
</rss>

