<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture - Client MAC address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4523035#M571912</link>
    <description>&lt;P&gt;Thank you Guys. It worked, created MAC address list and called it in Auth policies.&lt;/P&gt;&lt;P&gt;Added MAC address list in - Work Centers &amp;gt; Network Access &amp;gt; Identities&lt;/P&gt;&lt;P&gt;Created a MAC Group in - System Identity Management &amp;gt; Groups and added all MAC to it&lt;/P&gt;&lt;P&gt;Referred the MAC group in - Policy set &amp;gt; Authorization policy&lt;/P&gt;&lt;P&gt;Condition used - IdentityGroup Name Equals "Identity Group Name"&lt;/P&gt;&lt;P&gt;** Be sure to set DenyAccess Profile for Default Authorization policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 06:57:18 GMT</pubDate>
    <dc:creator>manvik</dc:creator>
    <dc:date>2021-12-23T06:57:18Z</dc:date>
    <item>
      <title>ISE Posture - Client MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522506#M571899</link>
      <description>&lt;P&gt;Can ISE only permit Remote VPN access from systems with permitted MAC address?&lt;/P&gt;&lt;P&gt;VPN used is anyconnect and it's authentication via ISE&lt;/P&gt;&lt;P&gt;Posturing like AV, OS etc are running successfully now&lt;/P&gt;&lt;P&gt;One more condition needs to add into posture, User MAC address (LAN or WiFi adapter MAC).&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 06:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522506#M571899</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2021-12-22T06:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture - Client MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522698#M571904</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can ISE only permit Remote VPN access from systems with permitted MAC address?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Pending that you have a list of the permitted MACs why not add a L2 mab identity group in the rad policy as another authz condition?&amp;nbsp; Have you tested that idea yet?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 12:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522698#M571904</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-12-22T12:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture - Client MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522895#M571907</link>
      <description>&lt;P&gt;In reply to Mike's comment, see if the Access-Request contains a Calling-Station-Id. I am unsure what MAC address will be contained there - wired or wireless - or in the worst case, a randomised MAC address.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 20:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4522895#M571907</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-12-22T20:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture - Client MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4523035#M571912</link>
      <description>&lt;P&gt;Thank you Guys. It worked, created MAC address list and called it in Auth policies.&lt;/P&gt;&lt;P&gt;Added MAC address list in - Work Centers &amp;gt; Network Access &amp;gt; Identities&lt;/P&gt;&lt;P&gt;Created a MAC Group in - System Identity Management &amp;gt; Groups and added all MAC to it&lt;/P&gt;&lt;P&gt;Referred the MAC group in - Policy set &amp;gt; Authorization policy&lt;/P&gt;&lt;P&gt;Condition used - IdentityGroup Name Equals "Identity Group Name"&lt;/P&gt;&lt;P&gt;** Be sure to set DenyAccess Profile for Default Authorization policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 06:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-client-mac-address/m-p/4523035#M571912</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2021-12-23T06:57:18Z</dc:date>
    </item>
  </channel>
</rss>

