<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3.0 and MAB Configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479656#M570162</link>
    <description>&lt;P&gt;I finally found the Endpoing.LogicalProfile. I created a rule for the printer and hope it works. I will give a shot a today.&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Oct 2021 19:43:57 GMT</pubDate>
    <dc:creator>Robert Molina</dc:creator>
    <dc:date>2021-10-04T19:43:57Z</dc:date>
    <item>
      <title>ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478478#M570101</link>
      <description>&lt;P&gt;I am new to this and starting into configuring our ISE servers with policies for allowing endpoints to authenticate using 802.1X. I am taking a phased approach to this so I don't accidently shut down the whole network. After much research, I started with a policy set that allows network access using Wired MAB. In order to monitor, I first configured the switch with:&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group &lt;EM&gt;Groupname&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x start-stop group &lt;EM&gt;Groupname&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For the interfaces that I am testing on I configured it with:&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;authentication open&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x timeout supp-timeout 30&lt;/P&gt;&lt;P&gt;dot1max-req 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The associated endpoints all authenticated without issues using this format. Unfortunately this doesn't work when the endpoint is a printer. I added the command authentication control-direction in.&lt;/P&gt;&lt;P&gt;The printer would still not pass authentication and access to printer is lost. I don't have a specific policy set for the printers and I don't know how to write one up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone assist me? Thank you for your support&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 20:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478478#M570101</guid>
      <dc:creator>Robert Molina</dc:creator>
      <dc:date>2021-10-01T20:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478558#M570106</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/200979"&gt;@Robert Molina&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;a simple example:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Work Centers &amp;gt; Profiler &amp;gt; Profiling Policies &amp;gt; Logical Profiles&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;1. create a &lt;U&gt;&lt;STRONG&gt;Printer-Profiler&lt;/STRONG&gt;&lt;/U&gt; and at &lt;STRONG&gt;Assigned Policies&lt;/STRONG&gt; select your &lt;U&gt;Printer model&lt;/U&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;Note: if you don't find your Printer model, then create one at &lt;STRONG&gt;Profiling Policies&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At &lt;STRONG&gt;Policy &amp;gt; Policy Sets&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;1.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&amp;nbsp;&lt;EM&gt;Policy Set Name&lt;/EM&gt;: &lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Condition&lt;/EM&gt;: &lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; Note: you are able to find the &lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt; condition at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Library Conditions&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;2. &lt;STRONG&gt;Authentication Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Rule Name&lt;/EM&gt;: &lt;STRONG&gt;MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Condition&lt;/EM&gt;: &lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Use&lt;/EM&gt;: &lt;STRONG&gt;Internal Endpoints&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;3. &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Rule Name&lt;/EM&gt;: &lt;STRONG&gt;Printer-MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp; &lt;EM&gt;Condition&lt;/EM&gt;: &lt;STRONG&gt;Endpoint.LogicalProfile&lt;/STRONG&gt; &lt;U&gt;EQUALS &lt;STRONG&gt;Printer-Profiler&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sat, 02 Oct 2021 06:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478558#M570106</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-10-02T06:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478563#M570108</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Just one thing on top of what &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt; said. In the authentication&lt;BR /&gt;policy, modify the settings if authentication failed to continue instead of&lt;BR /&gt;reject. This is needed for mab.&lt;BR /&gt;&lt;BR /&gt;Also, before creating profiling policy, check in context visibility&lt;BR /&gt;》endpoints. It might be already profiled as ISE has a lot of pre-built&lt;BR /&gt;profiling policies.&lt;BR /&gt;&lt;BR /&gt;Regards, Mohammed Al Baqari&lt;BR /&gt;</description>
      <pubDate>Sat, 02 Oct 2021 06:18:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4478563#M570108</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-10-02T06:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479607#M570155</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. I attempted to follow you instructions, but I am having difficulty with step 3.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;3.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Rule Name&lt;/EM&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Printer-MAB&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Condition&lt;/EM&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Endpoint.LogicalProfile&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;EQUALS&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Printer-Profiler&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I went to Authorization Policy, gave it the rule name, but when I tried to implement the Condition, I couldn't find it or was I supposed to add it as I was building the policy but I can't find the logical profile condition. I already made a logical profile for our printers and it recognizes the printers that we have on the network. Can you provide a little more detail? I'll keep working on it while I wait for your answer.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 17:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479607#M570155</guid>
      <dc:creator>Robert Molina</dc:creator>
      <dc:date>2021-10-04T17:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479610#M570156</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reminding me. There are a lot of prebuilt profiling policies, but one of our printers is not listed, so I ended up building one for that specific printer. I will also remember to do the authentication to continue.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 18:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479610#M570156</guid>
      <dc:creator>Robert Molina</dc:creator>
      <dc:date>2021-10-04T18:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479656#M570162</link>
      <description>&lt;P&gt;I finally found the Endpoing.LogicalProfile. I created a rule for the printer and hope it works. I will give a shot a today.&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 19:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479656#M570162</guid>
      <dc:creator>Robert Molina</dc:creator>
      <dc:date>2021-10-04T19:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479660#M570163</link>
      <description>&lt;P&gt;I tried to make it work, but as soon as I implemented the Monitor ACL on the switch, I couldn't ping its IP and of course couldn't print.&lt;/P&gt;&lt;P&gt;I just have to wait until it shows up again. Of course, this particular printer is one that is not on the pre-built by Cisco. So I am going to have to change it back to using port-security.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 20:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4479660#M570163</guid>
      <dc:creator>Robert Molina</dc:creator>
      <dc:date>2021-10-04T20:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4698047#M577555</link>
      <description>&lt;P&gt;Hi Marcelo Morais,&lt;/P&gt;&lt;P&gt;Does Cisco ISE need to have advantage license if&amp;nbsp;I'd like to use profiler service ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 09:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4698047#M577555</guid>
      <dc:creator>tonyang</dc:creator>
      <dc:date>2022-10-04T09:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4699640#M577621</link>
      <description>&lt;P&gt;ISE profiling services do consume advantage license. Please check&amp;nbsp;&lt;A href="http://cs.co/ise-ordering" target="_self"&gt;ISE Ordering Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may try it by using the 90-day eval for 100-endpoints that comes with a fresh ISE install or factory reset.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 23:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4699640#M577621</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-10-06T23:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4699641#M577622</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/200979"&gt;@Robert Molina&lt;/a&gt;&amp;nbsp;What advised so far have been on how to classify/profiling your printer device. As to the switch configuration and ISE authorization policy rule and profile, please check&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;or watch one of our videos at &lt;A href="http://cs.co/ise-videos" target="_blank"&gt;http://cs.co/ise-videos&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 23:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4699641#M577622</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-10-06T23:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 and MAB Configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4700219#M577651</link>
      <description>&lt;P&gt;Thank you, hslai.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2022 14:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-and-mab-configuration/m-p/4700219#M577651</guid>
      <dc:creator>tonyang</dc:creator>
      <dc:date>2022-10-08T14:12:26Z</dc:date>
    </item>
  </channel>
</rss>

