<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE two or more Authentication Policy Result in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308067#M566170</link>
    <description>&lt;P&gt;Hello guys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would ask you the logic of have two o more Authentication Policy Result for a policy set's rule.&lt;/P&gt;&lt;P&gt;I mean, sometimes I saw on different Cisco ISE policy sets some policy set rules that has two or more result for the same conditions.&lt;/P&gt;&lt;P&gt;So, in which way ISE apply one or the other? for my understanding the condition are the same.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Americo&lt;/P&gt;</description>
    <pubDate>Tue, 16 Mar 2021 11:32:25 GMT</pubDate>
    <dc:creator>Americo Massotti</dc:creator>
    <dc:date>2021-03-16T11:32:25Z</dc:date>
    <item>
      <title>Cisco ISE two or more Authentication Policy Result</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308067#M566170</link>
      <description>&lt;P&gt;Hello guys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would ask you the logic of have two o more Authentication Policy Result for a policy set's rule.&lt;/P&gt;&lt;P&gt;I mean, sometimes I saw on different Cisco ISE policy sets some policy set rules that has two or more result for the same conditions.&lt;/P&gt;&lt;P&gt;So, in which way ISE apply one or the other? for my understanding the condition are the same.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Americo&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 11:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308067#M566170</guid>
      <dc:creator>Americo Massotti</dc:creator>
      <dc:date>2021-03-16T11:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE two or more Authentication Policy Result</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308144#M566178</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/491474"&gt;@Americo Massotti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;please take a look at: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0100101.html" target="_blank" rel="noopener"&gt;ISE Admin Guide - Policy Set&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Remember that:&lt;/P&gt;&lt;P&gt;".&lt;EM&gt;.. &lt;STRONG&gt;Policy sets&lt;/STRONG&gt; are configured &lt;U&gt;hierarchically&lt;/U&gt;, where the rule on the &lt;U&gt;top level&lt;/U&gt; of the policy set, which can be viewed from the Policy Set table, applies to the entire set and is &lt;U&gt;matched before&lt;/U&gt; the rules for the rest of the policies and exceptions. Thereafter, rules of the set are applied in this order:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Authentication policy rules&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local policy exceptions&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Global policy exceptions&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Authorization policy rules...&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 13:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308144#M566178</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-16T13:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE two or more Authentication Policy Result</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308620#M566201</link>
      <description>&lt;P&gt;If more than one authorization profiles in the same result cell, then the attributes would be combined but only the first value will apply if the attribute may have only one. For example,&lt;/P&gt;
&lt;P&gt;authzProfile-1: VLAN=Employees, DACL=permitALL&lt;/P&gt;
&lt;P&gt;authzProfile-2: VLAN=ACCESS, Reauthentication with Timer=1800&lt;/P&gt;
&lt;P&gt;SecureGroup=Employees&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The combined shall be:&amp;nbsp;VLAN=Employees, DACL=permitALL,&amp;nbsp;Reauthentication with Timer=1800,&amp;nbsp;SecureGroup=Employees&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 03:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-or-more-authentication-policy-result/m-p/4308620#M566201</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-03-17T03:31:44Z</dc:date>
    </item>
  </channel>
</rss>

