<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dot1x ISE policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137373#M590318</link>
    <description>&lt;P&gt;Im building two Dot1x policies in ISE. One wired, the other wireless. As the end devices are the same and can connect either wired or wireless, the only difference in the policy is the wired or wireless dot1x condition selected from Condition Studio. However, when either wired or wireless connect they are using the wired policy as its the first policy.&lt;/P&gt;&lt;P&gt;Why is the wireless device hitting the wired policy if only wired_802.1x condition is set?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jun 2024 09:30:29 GMT</pubDate>
    <dc:creator>michael18</dc:creator>
    <dc:date>2024-06-28T09:30:29Z</dc:date>
    <item>
      <title>Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137373#M590318</link>
      <description>&lt;P&gt;Im building two Dot1x policies in ISE. One wired, the other wireless. As the end devices are the same and can connect either wired or wireless, the only difference in the policy is the wired or wireless dot1x condition selected from Condition Studio. However, when either wired or wireless connect they are using the wired policy as its the first policy.&lt;/P&gt;&lt;P&gt;Why is the wireless device hitting the wired policy if only wired_802.1x condition is set?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 09:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137373#M590318</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2024-06-28T09:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137387#M590319</link>
      <description>&lt;P&gt;can I see screen shoot of policy set&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 10:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137387#M590319</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-28T10:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137479#M590320</link>
      <description>&lt;P&gt;screen shot attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 12:23:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137479#M590320</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2024-06-28T12:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137489#M590321</link>
      <description>&lt;P&gt;in this screen i see its using wired-dot1x policy from a wireless device. NAS is the WLC&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221896iC84379D428760C13/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture1.JPG" alt="Capture1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 12:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137489#M590321</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2024-06-28T12:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137559#M590322</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/21339"&gt;@michael18&lt;/a&gt; &lt;/P&gt;
&lt;P&gt;The connection is processed by the Wired-Dot1x Policy Set because you are currently matching on username starts with "host/"&amp;nbsp;&amp;nbsp; (albeit that rule appears to be currently disabled). Subsequently, the wireless connection is matching on the "Wired-Dot1x &amp;gt; Default" Authentication Policy because it's not a Wired authentication.&amp;nbsp; Set the condition on the Policy Set itself to be "Wired_802.1X" only if you want only Wired 802.1X connections processed by that policy set.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then make sure in your Wireless Policy Set you match on the condition "Wireless_802.1X"&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 13:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137559#M590322</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-06-28T13:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137581#M590323</link>
      <description>&lt;P&gt;Is there a reason you are not using the wired/wireless conditions in the policy set vs the rule?&lt;/P&gt;
&lt;P&gt;You have to think of ISE like a firewall, the conditions at the start will drop them into that policy set and run the rules. Since you are calling the host name only it will hit weather wired or wireless.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-28 091813.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221936i10CB229EC99E4563/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-28 091813.jpg" alt="Screenshot 2024-06-28 091813.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 14:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137581#M590323</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-06-28T14:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137587#M590324</link>
      <description>&lt;P&gt;Aw of course. That makes sense now you point it out.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 14:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5137587#M590324</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2024-06-28T14:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x ISE policy</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5138320#M590348</link>
      <description>&lt;P&gt;Hi Dustan&lt;/P&gt;&lt;P&gt;just lack of experience, following guides and videos. There seems to be many ways to build ISE policies but I do see the benefit in the way you set it out. Its given me a bit to think about going forward.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 07:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-ise-policy/m-p/5138320#M590348</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2024-07-01T07:07:21Z</dc:date>
    </item>
  </channel>
</rss>

