<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388866#M566781</link>
    <description>I appreciate that. And if I was using a version that presented an&lt;BR /&gt;authorization policy in the policy set configuration I think I would have&lt;BR /&gt;it. When I add a condition in the policy set this is what I get:&lt;BR /&gt;&lt;BR /&gt;[image: image.png]&lt;BR /&gt;&lt;BR /&gt;And there is no way to use the CUSTOMATTRIBUTE dictionary that my custom&lt;BR /&gt;endpoint items exist in in a policy set, what am I missing?&lt;BR /&gt;&lt;BR /&gt;[image: image.png]&lt;BR /&gt;</description>
    <pubDate>Sat, 17 Apr 2021 22:38:08 GMT</pubDate>
    <dc:creator>Odysseu$</dc:creator>
    <dc:date>2021-04-17T22:38:08Z</dc:date>
    <item>
      <title>How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388858#M566779</link>
      <description>&lt;P&gt;I would like to use an endpoint custom attribute to trigger the network access a device has.&amp;nbsp; So as an example if I have a device that has a endpoint custom attribute of Display, I would like to use that as a condition to assign a specific DACL or vlan to that device while it is on the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone point me in the right direction to get this done?&amp;nbsp; I have created a results with authorization profiles for each the vlan and one for the dacl but I do not know how to apply them in a policy set.&amp;nbsp; I would imagine the logic would be if you connected via wired or wireless mab and the device has a custom endpoint attribute assigned where the "custom device type" equals "Display" then either change the vlan or use a downloadable acl to control access for that device.&amp;nbsp; I just can't figure out how to do that, and I haven't found a resource (video, article, configuration guide) that covers limiting access based on custom endpoint attributes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help is appreciated.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 21:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388858#M566779</guid>
      <dc:creator>Odysseu$</dc:creator>
      <dc:date>2021-04-17T21:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388859#M566780</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure-per-user-dynamic-access-contro.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure-per-user-dynamic-access-contro.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 21:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388859#M566780</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-04-17T21:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388866#M566781</link>
      <description>I appreciate that. And if I was using a version that presented an&lt;BR /&gt;authorization policy in the policy set configuration I think I would have&lt;BR /&gt;it. When I add a condition in the policy set this is what I get:&lt;BR /&gt;&lt;BR /&gt;[image: image.png]&lt;BR /&gt;&lt;BR /&gt;And there is no way to use the CUSTOMATTRIBUTE dictionary that my custom&lt;BR /&gt;endpoint items exist in in a policy set, what am I missing?&lt;BR /&gt;&lt;BR /&gt;[image: image.png]&lt;BR /&gt;</description>
      <pubDate>Sat, 17 Apr 2021 22:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388866#M566781</guid>
      <dc:creator>Odysseu$</dc:creator>
      <dc:date>2021-04-17T22:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388889#M566782</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1024004"&gt;@Odysseu$&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;create your &lt;STRONG&gt;Endpoint Custom Attribute&lt;/STRONG&gt; at:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Settings &amp;gt; Endpoint Custom Attribute&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="01.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/118320i99742A2C02106E6C/image-size/large?v=v2&amp;amp;px=999" role="button" title="01.png" alt="01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;Policy &amp;gt; Policy Set &amp;gt;&lt;/STRONG&gt; select your Policy &lt;STRONG&gt;&amp;gt; Authorization Policy&lt;/STRONG&gt; ... at the &lt;STRONG&gt;Attribute&lt;/STRONG&gt; condition, type your &lt;STRONG&gt;Custom Attribute&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="02.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/118321i1FF3E03454D08783/image-size/large?v=v2&amp;amp;px=999" role="button" title="02.png" alt="02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 04:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388889#M566782</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-18T04:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388988#M566786</link>
      <description>&lt;P&gt;Thanks for that and what you are showing is what I expect to see.&amp;nbsp; The question is how do I get the attribute to show up in a library for a policy?&amp;nbsp; I find no where in my libraries the ability to use that custom endpoint attribute.&amp;nbsp; In your picture it appears to have endpoints having a CustomAttr field...how did that happen?&amp;nbsp; My point is I cannot connect the dots from creating the attribute to having it actually appear as an option in a policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 12:17:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4388988#M566786</guid>
      <dc:creator>Odysseu$</dc:creator>
      <dc:date>2021-04-18T12:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389021#M566788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1024004"&gt;@Odysseu$&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;please double check if you are not trying to add the &lt;STRONG&gt;Endpoint Custom Attribute&lt;/STRONG&gt; in the &lt;STRONG&gt;Authentication Policy&lt;/STRONG&gt; ... for this kind of &lt;STRONG&gt;Conditions&lt;/STRONG&gt; you should add it in the &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 17:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389021#M566788</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-18T17:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389092#M566792</link>
      <description>&lt;P&gt;In addition to the information provided by Marcelo for defining the Endpoint Custom Attribute and creating a Condition and/or Authorisation Policy to use it, the endpoint needs to be associated with that attribute.&lt;/P&gt;
&lt;P&gt;If the attribute is not being provided by an External Identity Source like AD, you will need to manually edit the endpoint in Context Visibility and assign the custom attribute you defined.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Creating the attribute&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-19 at 11.49.56 am.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/118366iF40C0312961392C7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-19 at 11.49.56 am.png" alt="Screen Shot 2021-04-19 at 11.49.56 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Defining the AuthZ Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-19 at 11.53.13 am.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/118365i340E747E4CB00009/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-19 at 11.53.13 am.png" alt="Screen Shot 2021-04-19 at 11.53.13 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Assigning the attribute to the Endpoint&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-19 at 11.53.39 am.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/118364iDF1F9E75655A76F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-19 at 11.53.39 am.png" alt="Screen Shot 2021-04-19 at 11.53.39 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 01:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389092#M566792</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-04-19T01:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389364#M566801</link>
      <description>&lt;P&gt;So one thing for anyone who reads this.&amp;nbsp; To get the authorization policy to show.&amp;nbsp; This is what must be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a policy set.&amp;nbsp; Add some form of connectivity as the condition (802.1x, MAB, etc) then SAVE THE POLICY (key thing not mentioned anywhere).&amp;nbsp; After you save the policy there is a big &lt;FONT size="5"&gt;&lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt;&lt;/FONT&gt; at the end of the policy (notice there is nothing that says this is how you find authorization policy) if you click on the big &lt;FONT size="5"&gt;&lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; &lt;/FONT&gt;it will expand out the policy and behold the authorization policy makes its appearance.&amp;nbsp; If you try to click on &lt;FONT size="5"&gt;&lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt;&lt;/FONT&gt; without saving, it doesn't work and you can't see the authorization policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you everyone that helped.&amp;nbsp; All of your replies are all true and part of the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 12:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4389364#M566801</guid>
      <dc:creator>Odysseu$</dc:creator>
      <dc:date>2021-04-19T12:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Endpoint Custom Attributes to control network access (DACL or VLAN)?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4390405#M566814</link>
      <description>&lt;P&gt;This is demonstrated with &lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623" target="_self"&gt;ISE ERS APIs&lt;/A&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: disc; margin-left: 15px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--972098705" rel="nofollow noopener noreferrer" target="_blank"&gt;Create an Endpoint with Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-1644496847" rel="nofollow noopener noreferrer" target="_blank"&gt;Define ISE Endpoint Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--162957616" rel="nofollow noopener noreferrer" target="_blank"&gt;Create an Endpoint with Custom Attributes&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 00:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-use-endpoint-custom-attributes-to-control-network-access/m-p/4390405#M566814</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-04-21T00:09:50Z</dc:date>
    </item>
  </channel>
</rss>

