<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication PSK &amp;amp; MAC-filtering for RADIUS AuthZ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-psk-amp-mac-filtering-for-radius-authz/m-p/5171607#M591654</link>
    <description>&lt;P&gt;found confirmation here&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-only-be-authorization-for-wireless-users/td-p/3863947" target="_blank"&gt;Solved: ISE only be authorization for wireless users - Cisco Community&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 10:29:22 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2024-09-05T10:29:22Z</dc:date>
    <item>
      <title>Authentication PSK &amp; MAC-filtering for RADIUS AuthZ</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-psk-amp-mac-filtering-for-radius-authz/m-p/5171537#M591648</link>
      <description>&lt;P&gt;trying to fill the gap here:&lt;BR /&gt;1) PSK authenticated SSID mapped to default L2VNID#1 (VLAN)&lt;BR /&gt;2) depending on the MAC-address client of SSID must be landed in either default or non-default L2VNID#2&lt;BR /&gt;u decide apply MAC-filtering to SSID &amp;amp; direct WLC to request ISE for AuthZ where u have configured non-default rule to match endpoint's MAC against designated EID-group &amp;amp; to return L2VNID#2 in Tunnel-Private-Group-ID. Default rule just returns AccessAccept (it's still needed for the rest of endpoints). Now u need all MACs targeted for&amp;nbsp;L2VNID#2 to be members of&amp;nbsp;designated EID-group. &amp;amp; u think u dont need to list rest of clients of SSID anywhere bc successful authentication requires matching proper PSK only. Everything looks good until u recall all clients of SSID are now subject of AuthC. u could configure default AuthC rule to use Internal Endpoints &amp;amp; it would do the job for that endpoints u coded as members of&amp;nbsp;designated EID-group. But what to do for the rest of endpoints? u dont want to create separate EID-group for them. u think then about modifying default AuthC rule to look like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andydoesntlikeuucp_0-1725525006894.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227863iD7604436CE3E446E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="andydoesntlikeuucp_0-1725525006894.png" alt="andydoesntlikeuucp_0-1725525006894.png" /&gt;&lt;/span&gt;&lt;BR /&gt;do u achieve the goal at this point? any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 08:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-psk-amp-mac-filtering-for-radius-authz/m-p/5171537#M591648</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-09-05T08:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication PSK &amp; MAC-filtering for RADIUS AuthZ</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-psk-amp-mac-filtering-for-radius-authz/m-p/5171607#M591654</link>
      <description>&lt;P&gt;found confirmation here&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-only-be-authorization-for-wireless-users/td-p/3863947" target="_blank"&gt;Solved: ISE only be authorization for wireless users - Cisco Community&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 10:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-psk-amp-mac-filtering-for-radius-authz/m-p/5171607#M591654</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-09-05T10:29:22Z</dc:date>
    </item>
  </channel>
</rss>

