<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create Profiling Policies for a Group of Devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425631#M568213</link>
    <description>&lt;P&gt;Hey Marcelo,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Checked the Profiling Policy and it is enabled and I had both Certainty Factors set to 10. Not sure if it mattered, so changed them both to 5 and saved the policy. The Policy Name is called "Zoom_Phones".&lt;/P&gt;&lt;P&gt;The only Rule is that it needs to match the first 8 characters of the MACAddress.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Profiling_Policy.jpg" style="width: 757px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123964iCFE30EE295FE1760/image-size/large?v=v2&amp;amp;px=999" role="button" title="Profiling_Policy.jpg" alt="Profiling_Policy.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the Policy Set:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy-Set.jpg" style="width: 580px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123965iA6CCD5A2AA9164B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy-Set.jpg" alt="Policy-Set.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, when I check Radius Live Logs, I just get "&lt;EM&gt;Deny Access"&lt;/EM&gt;, and the Endpoint Profile showing as "&lt;EM&gt;Unknown"&lt;/EM&gt;. The first 8 characters of the MAC Address definitely matches the Rule in the Profiling Policy. I also tried plugging in a second device, also with the same first 8 in the MAC and it's getting the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 18:46:25 GMT</pubDate>
    <dc:creator>Matthew Martin</dc:creator>
    <dc:date>2021-06-29T18:46:25Z</dc:date>
    <item>
      <title>Create Profiling Policies for a Group of Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425077#M568176</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a group of devices that I want to create a new Profiling Policy for based off their MAC Addresses. All of the devices all start with the same first 8 characters of their Mac Address.&lt;/P&gt;&lt;P&gt;So I created a new Profiling Policy &lt;EM&gt;(*Policy &amp;gt; Profiling &amp;gt; Profiling Policies)&lt;/EM&gt;. In there I added 1 Rule, which is the only rule right now for &lt;EM&gt;"MAC:MACAddress&amp;nbsp; STARTSWITH&amp;nbsp; aabbccdd"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;Then, I went to my Wired Policy Sets. Created a new Authorization Policy with only one condition for &lt;EM&gt;"Endpoint Identity Groups:Profiled: &lt;U&gt;my_profile_name&lt;/U&gt;"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;Lastly, I plugged in the device. But, it's showing up as Unknown, instead of matching the Profiling Policy...&lt;/P&gt;&lt;P&gt;I also noticed there's &lt;STRONG&gt;Profiling Conditions&lt;/STRONG&gt; in &lt;EM&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Profiling&lt;/EM&gt;.... So I also added a policy condition there that does the same thing as the &lt;EM&gt;Profiling Policy&lt;/EM&gt; I described above with the &lt;EM&gt;Mac Address starts with&lt;/EM&gt;.... But, I assume this "condition" needs to be applied somewhere.&lt;/P&gt;&lt;P&gt;I'm thinking I'm missing something. Could anyone lend a hand with this, or point me in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 21:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425077#M568176</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2021-06-28T21:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Create Profiling Policies for a Group of Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425086#M568178</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325526"&gt;@Matthew Martin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;at &lt;STRONG&gt;Policy &amp;gt; Profiling &amp;gt; Profiling Policies&lt;/STRONG&gt;, double check if:&lt;BR /&gt;. the &lt;STRONG&gt;Policy&lt;/STRONG&gt;&amp;nbsp;is &lt;STRONG&gt;Enabled&lt;/STRONG&gt;.&lt;BR /&gt;. the &lt;STRONG&gt;Minimum Certainty Factor&lt;/STRONG&gt; matches the number of your rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ProfilerPolicy.png" style="width: 693px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123907i7A7BC8C3140CFA8A/image-dimensions/693x367?v=v2" width="693" height="367" role="button" title="ProfilerPolicy.png" alt="ProfilerPolicy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;Policy Set &amp;gt; Authorization Policy&lt;/STRONG&gt; double check if you are using&lt;BR /&gt;&lt;STRONG&gt;IndentityGroup.Name&lt;/STRONG&gt; EQUALS &lt;EM&gt;xxxx&lt;/EM&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;STRONG&gt;Endpoint.EndpointPolicy&lt;/STRONG&gt; EQUALS &lt;EM&gt;xxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 22:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425086#M568178</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-06-28T22:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Create Profiling Policies for a Group of Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425631#M568213</link>
      <description>&lt;P&gt;Hey Marcelo,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Checked the Profiling Policy and it is enabled and I had both Certainty Factors set to 10. Not sure if it mattered, so changed them both to 5 and saved the policy. The Policy Name is called "Zoom_Phones".&lt;/P&gt;&lt;P&gt;The only Rule is that it needs to match the first 8 characters of the MACAddress.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Profiling_Policy.jpg" style="width: 757px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123964iCFE30EE295FE1760/image-size/large?v=v2&amp;amp;px=999" role="button" title="Profiling_Policy.jpg" alt="Profiling_Policy.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the Policy Set:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy-Set.jpg" style="width: 580px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123965iA6CCD5A2AA9164B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy-Set.jpg" alt="Policy-Set.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, when I check Radius Live Logs, I just get "&lt;EM&gt;Deny Access"&lt;/EM&gt;, and the Endpoint Profile showing as "&lt;EM&gt;Unknown"&lt;/EM&gt;. The first 8 characters of the MAC Address definitely matches the Rule in the Profiling Policy. I also tried plugging in a second device, also with the same first 8 in the MAC and it's getting the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 18:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4425631#M568213</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2021-06-29T18:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create Profiling Policies for a Group of Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4428148#M568315</link>
      <description>&lt;P&gt;The separators might not have matched properly.&lt;/P&gt;
&lt;P&gt;Also, we could use RADIUS:Calling-Station-ID directly in authorization conditions.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-07-05 at 8.38.37 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/124418i9B2938D5B95768AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-07-05 at 8.38.37 AM.png" alt="Screen Shot 2021-07-05 at 8.38.37 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/create-profiling-policies-for-a-group-of-devices/m-p/4428148#M568315</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-07-05T15:42:09Z</dc:date>
    </item>
  </channel>
</rss>

