<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE : How to differentiate between AD Users AD and proxy radius us in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4837959#M581803</link>
    <description>&lt;P&gt;This sounds similar to the Eduroam use case example found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/configuring-eduroam-on-cisco-identity-services-engine-ise/ta-p/3655672" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/configuring-eduroam-on-cisco-identity-services-engine-ise/ta-p/3655672&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You would need the username presented to ISE to differentiate between users in your realm (authenticated by your AD) versus users in another realm (proxied). Your Policy Set matching conditions would be based on those attributes.&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 22:27:04 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2023-05-17T22:27:04Z</dc:date>
    <item>
      <title>ISE : How to differentiate between AD Users AD and proxy radius users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4837557#M581787</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;i am looking of a way to differentiate between two kind of dot1x users:&lt;/P&gt;&lt;P&gt;1. Users that have to go through AD which is correctly configured as identity source in ISE and this rule is the only active rule in policy sets&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Users that go through proxy radius which also work correctly when this rule&amp;nbsp;is the only active in policy sets&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when i activate both rules, the proxy radius based users fail to authenticate when the AD rule is configured firstly and the same is true when the proxy radius rule is configured firstly then the AD users fail.&lt;/P&gt;&lt;P&gt;The problem as i see it is because the condition in the Policy sets is the same that is : Normalised Radius Flow Type EQUALS wired802_1x.&lt;/P&gt;&lt;P&gt;Any ideas how could i differentiate between these two flows (AD flow and Proxy radius flow)?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 10:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4837557#M581787</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2023-05-17T10:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : How to differentiate between AD Users AD and proxy radius us</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4837959#M581803</link>
      <description>&lt;P&gt;This sounds similar to the Eduroam use case example found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/configuring-eduroam-on-cisco-identity-services-engine-ise/ta-p/3655672" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/configuring-eduroam-on-cisco-identity-services-engine-ise/ta-p/3655672&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You would need the username presented to ISE to differentiate between users in your realm (authenticated by your AD) versus users in another realm (proxied). Your Policy Set matching conditions would be based on those attributes.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 22:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4837959#M581803</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-05-17T22:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : How to differentiate between AD Users AD and proxy radius us</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4838834#M581830</link>
      <description>&lt;P&gt;Thanks for the document. I added an AND statement in the two conditions to differentiate between users , something like the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normalised Radius Flow TYpe AND Radius User-Name contains (or NOT contains) the realm i want in order to send some users to proxy radius and some others in the Active Directory.&lt;/P&gt;&lt;P&gt;It seems that it is working in a way.&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 08:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-how-to-differentiate-between-ad-users-ad-and-proxy-radius/m-p/4838834#M581830</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2023-05-19T08:24:34Z</dc:date>
    </item>
  </channel>
</rss>

