<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure to process policy set by policy set at ISE 3.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4751763#M579142</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;for the input. When i modify condition by adding devices group. it works well.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2023 05:24:40 GMT</pubDate>
    <dc:creator>journey jane</dc:creator>
    <dc:date>2023-01-10T05:24:40Z</dc:date>
    <item>
      <title>How to configure to process policy set by policy set at ISE 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750682#M579128</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;Let me ask some helps regarding ISE multiple policy set, i'm trying to configure my policy sets to get segregate for each.&lt;/P&gt;&lt;P&gt;For example, we have two policy set as (&lt;SPAN&gt;Building1st-Posture-PolicySet and&amp;nbsp;Building2nd-Posture-PolicySet&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;For each policy set, i have authorization and authentication policies for multiple departments. As i expected is 'If user not found at &lt;SPAN&gt;Building2nd-Posture-PolicySet&lt;/SPAN&gt; and it should not meeting with any authorization profile and it should go on to check user at &lt;SPAN&gt;Building1st-Posture-PolicySet&lt;/SPAN&gt; and apply authorization profile accordingly but it does not work as expected and if user not found at &lt;SPAN&gt;Building2nd-Posture-PolicySet&lt;/SPAN&gt;, it get reject with Default-Deny of Authorization policy of&amp;nbsp;&lt;SPAN&gt;Building2nd-Posture-PolicySet&lt;/SPAN&gt; and did not continue to process top-to-down until&amp;nbsp;&lt;SPAN&gt;Building1st-Posture-PolicySet. So, all of users who are at&amp;nbsp;Building1st-Posture-PolicySet get Deny.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How can i configure to process top-to-down policy set by policy set? Is there anyone experienced about that? Thanks.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="journeyjane_0-1673064606384.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172694iB1F65564870B7E29/image-size/medium?v=v2&amp;amp;px=400" role="button" title="journeyjane_0-1673064606384.png" alt="journeyjane_0-1673064606384.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="journeyjane_1-1673064647980.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172695i8A27D92C6BE06CED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="journeyjane_1-1673064647980.png" alt="journeyjane_1-1673064647980.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 04:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750682#M579128</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2023-01-07T04:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure to process policy set by policy set at ISE 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750705#M579129</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1276902"&gt;@journey jane&lt;/a&gt; at present the conditions to match the Policy Sets are identical (Wired Dot1x and Wired MAB). You need to distinguish between them with an additional unique condition. You can group the NAD (switches) for each building in to a different Network Device Group (NDG) and use this in the policy set to distinguish between the different connection requests depending where they are coming from.&lt;/P&gt;
&lt;P&gt;I personally would just combine those 2 Policy Sets&amp;nbsp; into 1 and use the different conditions within the authorisation rules to achieve the same result.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 08:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750705#M579129</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-07T08:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure to process policy set by policy set at ISE 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750812#M579130</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1276902"&gt;@journey jane&lt;/a&gt;&amp;nbsp;, the approach that I would take is to add an extra condition within the couple of policy sets that you have created in order to differentiate if the request is coming from building 1 or 2, the easiest way it would be if you create a device group and involves all the NAD that you have in building 1 and then use a condition like the one below ( notice that instead of SWITCH it would have to be the NAD group of building 1) ,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RodrigoDiaz_0-1673109788249.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172733i1BF6B5EC227C10FB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RodrigoDiaz_0-1673109788249.png" alt="RodrigoDiaz_0-1673109788249.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;for further reference :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_secure_wired_access.html#ID1661" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_secure_wired_access.html#ID1661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 16:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4750812#M579130</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-01-07T16:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure to process policy set by policy set at ISE 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4751763#M579142</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;for the input. When i modify condition by adding devices group. it works well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 05:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4751763#M579142</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2023-01-10T05:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure to process policy set by policy set at ISE 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4751764#M579143</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/632778"&gt;@Rodrigo Diaz&lt;/a&gt;&amp;nbsp; for the input. When i modify condition by adding devices group as you mentioned. it works well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 05:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-to-process-policy-set-by-policy-set-at-ise-3-0/m-p/4751764#M579143</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2023-01-10T05:25:33Z</dc:date>
    </item>
  </channel>
</rss>

