<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Policies TACACS+ Parent Group attribute in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522455#M571896</link>
    <description>&lt;P&gt;AFAIK, the Parent/Child hierarchy of NDGs was always just for logical grouping and condition matching of Child groups based on using the Parent group was never supported on any current/prior versions of ISE. The &lt;STRONG&gt;Equals&lt;/STRONG&gt; operator typically indicates an exact string match in ISE, so ISE would not match on the partial string of the Parent group.&lt;/P&gt;
&lt;P&gt;I have always leveraged the OR matching condition suggested by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt; to prevent any potential mis-matches,&amp;nbsp;but you could also try using either the &lt;STRONG&gt;Starts with&lt;/STRONG&gt; or &lt;STRONG&gt;Contains&lt;/STRONG&gt; operators in your condition rather than Equals. Those operators should allow the string match based on the partial Parent group.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 03:24:41 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-12-22T03:24:41Z</dc:date>
    <item>
      <title>Cisco ISE Policies TACACS+ Parent Group attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4521925#M571866</link>
      <description>&lt;P&gt;ISE VM Evaluation (I'm doing this on testbed before I implement it on production for customer)&lt;/P&gt;&lt;P&gt;Version 3.0 patch 4 with log4j hotfix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem Description:&lt;BR /&gt;Whenever I use the parent group of the network device the policy does not seem to catch it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Device Group&lt;/P&gt;&lt;P&gt;All Device Type&lt;/P&gt;&lt;P&gt;- SWITCH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Device&lt;/P&gt;&lt;P&gt;L3-Switch&lt;/P&gt;&lt;P&gt;Device Type - SWITCH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device Admin Policy Set&lt;/P&gt;&lt;P&gt;Conditions (Does not work)&lt;/P&gt;&lt;P&gt;Device &amp;gt; Device Type = All Device Type&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does work is&lt;/P&gt;&lt;P&gt;Conditions&lt;/P&gt;&lt;P&gt;Device &amp;gt; Device Type = SWITCH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is this the expected behavior of the policy?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shouldn't it hit the policy since the SWITCH is the sub group of the Parent Group All Device Type&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also tried the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Device Group&lt;/P&gt;&lt;P&gt;All Device Type&lt;/P&gt;&lt;P&gt;- SWITCH &amp;gt; IOS-XE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Device&lt;/P&gt;&lt;P&gt;L3-Switch&lt;/P&gt;&lt;P&gt;Device Type - IOS-XE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device Admin Policy Set&lt;/P&gt;&lt;P&gt;Conditions (Does not work)&lt;/P&gt;&lt;P&gt;Device &amp;gt; Device Type = SWITCH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've attached some images for clarity.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 06:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4521925#M571866</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2021-12-21T06:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policies TACACS+ Parent Group attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522078#M571875</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/804751"&gt;@jj2048&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;the &lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#SW_IO-XE&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt; is&amp;nbsp;&lt;U&gt;true&lt;/U&gt;&lt;SPAN&gt; if a &lt;/SPAN&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;SPAN&gt; is &lt;/SPAN&gt;&lt;U&gt;equal&lt;/U&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;SW_IO-XE&lt;/STRONG&gt;&lt;SPAN&gt; or is &lt;/SPAN&gt;&lt;U&gt;equal&lt;/U&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;All Device.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: you are able to create a &lt;STRONG&gt;OR&lt;/STRONG&gt; condition to solve your problem, like:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#SW_IO-XE&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;or&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 10:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522078#M571875</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-12-21T10:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policies TACACS+ Parent Group attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522434#M571894</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that my understanding of how Network Device Parent group should work is not the same on how it should be applied on the policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my understanding, if I apply the &lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;All Device Type#SWITCH&amp;gt;&lt;/STRONG&gt;, the policy should have caught all child groups of &lt;STRONG&gt;SWITCH&lt;/STRONG&gt;, the same should be true on&amp;nbsp;&lt;STRONG&gt;All Device Type,&amp;nbsp;&lt;/STRONG&gt;which should have caught all the child groups of Device Types. I'll go check this on the lower versions as I know this is working, if my memory serves me right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happens on the actual policy is that, if I apply the&amp;nbsp;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;All Device Type#SWITCH&amp;gt;&lt;/STRONG&gt;, it &lt;STRONG&gt;only&lt;/STRONG&gt; catches the network device which is tagged as &lt;STRONG&gt;SWITCH&lt;/STRONG&gt;, which I think defeats the purpose of the parent groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although a workaround on my part is what you have said which will be OR condition, and to simplify it more, I have used the Library Condition Blocks in order to re-use the conditions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Library Condition Block Name: &lt;STRONG&gt;All Device Softwares&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#SW_IOS-XE&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;or&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#SW_NXOS&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;or&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#R_IOS-XE&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;or&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Condition: Device.DeviceType EQUALS &amp;lt;&lt;EM&gt;All Device Type#SWITCH#R_IOS-XR&lt;/EM&gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extra steps but it does the job for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll post again once I determine on version 2.7 if my understanding is correct on parent groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 00:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522434#M571894</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2021-12-22T00:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policies TACACS+ Parent Group attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522455#M571896</link>
      <description>&lt;P&gt;AFAIK, the Parent/Child hierarchy of NDGs was always just for logical grouping and condition matching of Child groups based on using the Parent group was never supported on any current/prior versions of ISE. The &lt;STRONG&gt;Equals&lt;/STRONG&gt; operator typically indicates an exact string match in ISE, so ISE would not match on the partial string of the Parent group.&lt;/P&gt;
&lt;P&gt;I have always leveraged the OR matching condition suggested by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt; to prevent any potential mis-matches,&amp;nbsp;but you could also try using either the &lt;STRONG&gt;Starts with&lt;/STRONG&gt; or &lt;STRONG&gt;Contains&lt;/STRONG&gt; operators in your condition rather than Equals. Those operators should allow the string match based on the partial Parent group.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 03:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policies-tacacs-parent-group-attribute/m-p/4522455#M571896</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-12-22T03:24:41Z</dc:date>
    </item>
  </channel>
</rss>

