<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture with static addressing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606282#M574618</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/575098"&gt;@iVicMMac&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;if my understanding is correct, you would like &lt;U&gt;not only&lt;/U&gt; to use the &lt;STRONG&gt;IP Addr&lt;/STRONG&gt; of the &lt;STRONG&gt;Device&lt;/STRONG&gt; as a &lt;STRONG&gt;Condition&lt;/STRONG&gt; to the &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;, but also check the &lt;STRONG&gt;Posture&lt;/STRONG&gt; status, please try the following (as an example):&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At &lt;STRONG&gt;Policy &amp;gt; Policy Set&lt;/STRONG&gt;, you created a &lt;STRONG&gt;Wired-Policy&lt;/STRONG&gt;, for ex.:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Rule Name:&amp;nbsp;&lt;U&gt;&lt;EM&gt;John-Doe-AuthZPolicy-Compliant&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Condition:&amp;nbsp; &lt;EM&gt;&lt;U&gt;Network Access.Device IP Address Equals 10.10.10.1&lt;/U&gt;&lt;/EM&gt; AND&amp;nbsp;&lt;EM&gt;&lt;U&gt;Session.PostureStatus Equals Compliant&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Result: &lt;EM&gt;&lt;U&gt;&amp;lt;AuthZ Profiles Result for Posture Compliant&amp;gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Rule Name:&amp;nbsp;&lt;U&gt;&lt;EM&gt;John-Doe-AuthZPolicy-Unknown&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Condition:&amp;nbsp; &lt;EM&gt;&lt;U&gt;Network Access.Device IP Address Equals 10.10.10.1&lt;/U&gt;&lt;/EM&gt; AND&amp;nbsp;&lt;EM&gt;&lt;U&gt;Session.PostureStatus Equals Unknown&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Result: &lt;EM&gt;&lt;U&gt;&amp;lt;AuthZ Profiles Result for Posture Unknown&amp;gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Sun, 08 May 2022 01:37:23 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2022-05-08T01:37:23Z</dc:date>
    <item>
      <title>ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605464#M574599</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I'm struggling configuring the posture for +600 users with static addressing (this addressing is assigned by ISE) I can't make the ISE applies the iP address for each user plus works the ISE Posture at the same time within my policy, anyone can help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CISCO ISE 2.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 00:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605464#M574599</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2022-05-06T00:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605477#M574601</link>
      <description>&lt;P&gt;So you are using the ISE local DHCP server?&amp;nbsp; How is ISE assigning static IPs to clients?&amp;nbsp; IP Device Tracking enabled on the NAD?&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 01:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605477#M574601</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-06T01:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605494#M574603</link>
      <description>&lt;P&gt;Nope, all the addressing is static, no DHCP, I created each autorization profile with each framed iP, so this profile is the iP the user receives&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 02:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605494#M574603</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2022-05-06T02:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605680#M574607</link>
      <description>&lt;P&gt;Interesting.&amp;nbsp; What is the use-case here?&amp;nbsp; So you have 600 AuthZ profiles? One for each user?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 11:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4605680#M574607</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-06T11:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606150#M574614</link>
      <description>&lt;P&gt;Yes, its a customer requirement to have more control over the users&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2022 11:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606150#M574614</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2022-05-07T11:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606282#M574618</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/575098"&gt;@iVicMMac&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;if my understanding is correct, you would like &lt;U&gt;not only&lt;/U&gt; to use the &lt;STRONG&gt;IP Addr&lt;/STRONG&gt; of the &lt;STRONG&gt;Device&lt;/STRONG&gt; as a &lt;STRONG&gt;Condition&lt;/STRONG&gt; to the &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;, but also check the &lt;STRONG&gt;Posture&lt;/STRONG&gt; status, please try the following (as an example):&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At &lt;STRONG&gt;Policy &amp;gt; Policy Set&lt;/STRONG&gt;, you created a &lt;STRONG&gt;Wired-Policy&lt;/STRONG&gt;, for ex.:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Rule Name:&amp;nbsp;&lt;U&gt;&lt;EM&gt;John-Doe-AuthZPolicy-Compliant&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Condition:&amp;nbsp; &lt;EM&gt;&lt;U&gt;Network Access.Device IP Address Equals 10.10.10.1&lt;/U&gt;&lt;/EM&gt; AND&amp;nbsp;&lt;EM&gt;&lt;U&gt;Session.PostureStatus Equals Compliant&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Result: &lt;EM&gt;&lt;U&gt;&amp;lt;AuthZ Profiles Result for Posture Compliant&amp;gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Rule Name:&amp;nbsp;&lt;U&gt;&lt;EM&gt;John-Doe-AuthZPolicy-Unknown&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Condition:&amp;nbsp; &lt;EM&gt;&lt;U&gt;Network Access.Device IP Address Equals 10.10.10.1&lt;/U&gt;&lt;/EM&gt; AND&amp;nbsp;&lt;EM&gt;&lt;U&gt;Session.PostureStatus Equals Unknown&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Result: &lt;EM&gt;&lt;U&gt;&amp;lt;AuthZ Profiles Result for Posture Unknown&amp;gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 08 May 2022 01:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606282#M574618</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-08T01:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture with static addressing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606988#M574647</link>
      <description>&lt;P&gt;Thank you Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried a solution pretty similar last week and it seems is working &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; The difference is I configured only 1 policy for compliant and noncompliant at the end of policy set and the unknown condition for each user, a lot of work to add manually this condition but its ok. Thank you again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 17:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-with-static-addressing/m-p/4606988#M574647</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2022-05-09T17:08:07Z</dc:date>
    </item>
  </channel>
</rss>

