<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endstation Network Condition not working for IPv4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/5162054#M591266</link>
    <description>&lt;P&gt;Based on the definition, the only parameter that is checked when you select &lt;STRONG&gt;Endstation Network Condition&amp;nbsp;&lt;/STRONG&gt;and using RADIUS-based authentication is "&lt;STRONG&gt;Calling-Station-ID&lt;/STRONG&gt;". Based on your experience, the MAC address restriction works but IP address does not. This is normal because "&lt;STRONG&gt;Calling-Station-ID&lt;/STRONG&gt;" contains the ip address of the endstation when the endpoint is using AnyConnect VPN to access the network.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Aug 2024 10:52:27 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2024-08-17T10:52:27Z</dc:date>
    <item>
      <title>Endstation Network Condition not working for IPv4</title>
      <link>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4467450#M569726</link>
      <description>&lt;P&gt;I have a question about Endstation Network Conditions for IPv4.&lt;BR /&gt;I have configured “Network Conditions&amp;gt;&amp;gt;&amp;gt;Endstation Network Conditions&amp;gt;&amp;gt;&amp;gt;created „TEST_ENDSTATION” and added the address IP 10.50.50.10 or alternatively 10.50.50.0/24.&lt;BR /&gt;In AUTHORIZATION POLICY I have the condition „Network Conditions: TEST_ENDSTATION”.&lt;BR /&gt;Start endstation authentication/authorization with the address IP 10.50.50.10 (tested for MAB and DOT1X) is not matched with the prepared condition. I read that I need to add a command on the switch, &lt;SPAN&gt;but it doesn't help&lt;/SPAN&gt;:&lt;BR /&gt;radius-server attribute 31 send nas-port-detail.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i tried too&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;radius-server attribute 31 send nas-port-detail&lt;/P&gt;&lt;P&gt;radius-server attribute 31 remote-id&lt;/P&gt;&lt;P&gt;radius-server attribute 31 append-circuit-id&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, I have attributes for configuration:&lt;/P&gt;&lt;P&gt;mab request format attribute 32 vlan access-vlan&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server attribute 31 send nas-port-detail&lt;/P&gt;&lt;P&gt;radius-server attribute 31 remote-id&lt;/P&gt;&lt;P&gt;radius-server attribute 31 append-circuit-id&lt;/P&gt;&lt;P&gt;radius-server vsa send cisco-nas-port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did not work.&lt;BR /&gt;If I add MAC to Endstation Network Conditions &amp;gt;&amp;gt;&amp;gt; TEST_ENDSTATION MAC, then the authorization works correctly and goes to AUTHORIZATION POLICY condition "Network Conditions: TEST_ENDSTATION MAC".&lt;/P&gt;&lt;P&gt;So for MAC it works for IP it doesn't work.&lt;/P&gt;&lt;P&gt;What do I need to add to the switch configuration so that the IP address is sent in the network attributes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Port configuration:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/XX&lt;/P&gt;&lt;P&gt;&amp;nbsp;description dot1x test&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport access vlan XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport mode access&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport nonegotiate&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport voice vlan XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication event fail retry 0 action next-method&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication event server dead action authorize&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication open&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication order dot1x mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication port-control auto&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication periodic&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication timer inactivity server&lt;/P&gt;&lt;P&gt;&amp;nbsp;mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;no snmp trap link-status&lt;/P&gt;&lt;P&gt;&amp;nbsp;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;spanning-tree portfast edge&lt;/P&gt;&lt;P&gt;&amp;nbsp;spanning-tree guard root&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip dhcp snooping limit rate 15&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;Switch (&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;I also tested on others&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;WS-C2960C-8PC 15.2(7)E4 - C2960c405-UNIVERSALK9-M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="endstation MAC conditions.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/131040iF5013E25FE74C2CC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="endstation MAC conditions.png" alt="endstation MAC conditions.png" /&gt;&lt;/span&gt;  &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="endstation IP conditions.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/131039iFF3F753FA5704A15/image-size/medium?v=v2&amp;amp;px=400" role="button" title="endstation IP conditions.png" alt="endstation IP conditions.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 06:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4467450#M569726</guid>
      <dc:creator>newjard</dc:creator>
      <dc:date>2021-09-16T06:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Endstation Network Condition not working for IPv4</title>
      <link>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4468085#M569748</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1158095"&gt;@newjard&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;the &lt;STRONG&gt;Endstation Network Conditions&lt;/STRONG&gt; is based on &lt;STRONG&gt;End Stations&lt;/STRONG&gt; that initiate and terminate the connection. In a &lt;STRONG&gt;RADIUS Request&lt;/STRONG&gt;, this identifier is available in &lt;STRONG&gt;Attribute 31&lt;/STRONG&gt; (&lt;STRONG&gt;Calling-Station-Id&lt;/STRONG&gt;). &lt;STRONG&gt;Calling-Station-Id&lt;/STRONG&gt; is commonly the &lt;STRONG&gt;MAC Addr&lt;/STRONG&gt;&amp;nbsp;of the connecting &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;At&amp;nbsp;&lt;STRONG&gt;Work Centers &amp;gt; Profiler &amp;gt; Endpoint Classification&lt;/STRONG&gt;, check the attributes captured by the &lt;STRONG&gt;RADIUS Probe&lt;/STRONG&gt; of the selected &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;, verify the &lt;STRONG&gt;Calling-Station-Id&lt;/STRONG&gt; info.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: the &lt;STRONG&gt;Framed-IP-Address&lt;/STRONG&gt; value populates the &lt;STRONG&gt;IP&amp;nbsp;&lt;/STRONG&gt;attribute.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 00:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4468085#M569748</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-09-17T00:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Endstation Network Condition not working for IPv4</title>
      <link>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4468253#M569761</link>
      <description>&lt;P&gt;Thanks for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my endpoint authorization's ISE logs I have:&lt;/P&gt;&lt;P&gt;--------&lt;STRONG&gt;ISE LOGS&lt;/STRONG&gt;--------&lt;BR /&gt;&lt;STRONG&gt;Authentication Details&lt;/STRONG&gt;&lt;BR /&gt;Endpoint Id: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;Calling Station Id: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;IPv4 Address: 10.50.50.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Attributes&lt;/STRONG&gt;&lt;BR /&gt;EndPointMACAddress: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;Called-Station-ID: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;&lt;U&gt;-- I can't see Framed-IP-Address --&lt;/U&gt;&lt;/P&gt;&lt;P&gt;-----&lt;BR /&gt;In &lt;STRONG&gt;ISE&lt;/STRONG&gt; &lt;STRONG&gt;TCP DUMP in wireshark&lt;/STRONG&gt; I can see Framed-IP-Address:&lt;BR /&gt;AVP: t=Framed-IP-Address(8) l=6 val=10.50.50.10&lt;BR /&gt;Type: 8&lt;BR /&gt;Length: 6&lt;BR /&gt;Framed-IP-Address: 10.50.50.10&lt;BR /&gt;-----&lt;/P&gt;&lt;P&gt;At Work Centers &amp;gt; Profiler &amp;gt; &lt;STRONG&gt;Endpoint Classification&lt;/STRONG&gt; I can see:&lt;BR /&gt;Calling-Station-ID: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;EndPointMACAddress: &lt;EM&gt;MAC ENDPOINT&lt;/EM&gt;&lt;BR /&gt;Framed-IP-Address: 10.50.50.10&lt;BR /&gt;Ip: 10.50.50.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;We do not use Profiling.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;T&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;he authorization rule with IP_ENDPOINT still does not match.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;What else could be the reason? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;What can i check? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 07:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/4468253#M569761</guid>
      <dc:creator>newjard</dc:creator>
      <dc:date>2021-09-17T07:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Endstation Network Condition not working for IPv4</title>
      <link>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/5162054#M591266</link>
      <description>&lt;P&gt;Based on the definition, the only parameter that is checked when you select &lt;STRONG&gt;Endstation Network Condition&amp;nbsp;&lt;/STRONG&gt;and using RADIUS-based authentication is "&lt;STRONG&gt;Calling-Station-ID&lt;/STRONG&gt;". Based on your experience, the MAC address restriction works but IP address does not. This is normal because "&lt;STRONG&gt;Calling-Station-ID&lt;/STRONG&gt;" contains the ip address of the endstation when the endpoint is using AnyConnect VPN to access the network.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 10:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endstation-network-condition-not-working-for-ipv4/m-p/5162054#M591266</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-08-17T10:52:27Z</dc:date>
    </item>
  </channel>
</rss>

