<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Policy Set for Access-Points in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259148#M594899</link>
    <description>&lt;P&gt;If you have already a policy set and you don't want to create a separate one to authenticate and authorize the APs, then you can just add a new authentication rule to your existing MAB (assuming you will be doning MAB) policy specifying the device type and location in the authentication rule as conditions. Then you create a new authorization rule with the APs profile as a condition as shown in my post above.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 14:41:38 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2025-02-11T14:41:38Z</dc:date>
    <item>
      <title>Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259073#M594892</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we've a Cisco ISE 3.4 p1 and have some 802.1x and MAB Policies.&lt;/P&gt;&lt;P&gt;Now I want our Access-Points (Cisco-AP-Catalyst-9120AX) in an extra VLAN.&lt;/P&gt;&lt;P&gt;Under Context Visibility I see all the AP's with the Model, but don't get started.&lt;/P&gt;&lt;P&gt;New Policy-Set, should I use for Condition Device-Type: $Switch, like for the 802.1x and MAB Policy?&lt;/P&gt;&lt;P&gt;Where can can I use the Endpoint Profile "Cisco-AP-Catalyst-9120AX" in a Policy Set?&lt;/P&gt;&lt;P&gt;I know, in the Authorization Policy I can define the VLAN&lt;/P&gt;&lt;P&gt;any Help appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 11:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259073#M594892</guid>
      <dc:creator>gaigl</dc:creator>
      <dc:date>2025-02-11T11:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259093#M594893</link>
      <description>&lt;P&gt;Depends on how you want the match to be, if you want the match to be done based on device type or location, then you can add those conditions to your policy.&lt;/P&gt;
&lt;P&gt;If you want to use the AP profile as a condition then in the authorization rule you can select "EndPoints &amp;gt; EndPointPolicy" as the condition and then finally select the profile you want to use.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 12:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259093#M594893</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-11T12:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259137#M594895</link>
      <description>&lt;P&gt;OK, thank you!&lt;/P&gt;&lt;P&gt;I've got now the authorization Rule with the Endpoints, but what will be the Condition of the Policy-Set?&lt;/P&gt;&lt;P&gt;I could use "Device Type: Access-Switch", but what would I use for "Allowed Protocols / Server Sequence" ?&lt;/P&gt;&lt;P&gt;I think, anyway I have to differ from the 802.1x and MAB Policy.&lt;/P&gt;&lt;P&gt;Sorry, if I'm a little bit clueless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259137#M594895</guid>
      <dc:creator>gaigl</dc:creator>
      <dc:date>2025-02-11T14:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259143#M594897</link>
      <description>&lt;P&gt;You're welcome. Are you going to do MAB for the APs?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259143#M594897</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-11T14:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259148#M594899</link>
      <description>&lt;P&gt;If you have already a policy set and you don't want to create a separate one to authenticate and authorize the APs, then you can just add a new authentication rule to your existing MAB (assuming you will be doning MAB) policy specifying the device type and location in the authentication rule as conditions. Then you create a new authorization rule with the APs profile as a condition as shown in my post above.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259148#M594899</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-11T14:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259150#M594900</link>
      <description>&lt;P&gt;I'm not sure, the ISE knows the AP Model without work from me, could be from MAC Address.&lt;/P&gt;&lt;P&gt;Would be fine, if I don't need any Action, if a new AP is mounted.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259150#M594900</guid>
      <dc:creator>gaigl</dc:creator>
      <dc:date>2025-02-11T14:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259152#M594901</link>
      <description>&lt;P&gt;oh, I undestand, I'll try tomorrow&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259152#M594901</guid>
      <dc:creator>gaigl</dc:creator>
      <dc:date>2025-02-11T14:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259200#M594908</link>
      <description>&lt;P&gt;ISE has plenty of predefined profiles, if you look at the APs profile you would most likely see some attributes in addition to the OUI.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259200#M594908</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-11T16:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259508#M594922</link>
      <description>&lt;P&gt;Thanks a lot Aref, works as expected: new Authorization Rule in the MAB Policy Set&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 06:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259508#M594922</guid>
      <dc:creator>gaigl</dc:creator>
      <dc:date>2025-02-12T06:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy Set for Access-Points</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259590#M594924</link>
      <description>&lt;P&gt;You're very welcome, glad to be of help.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 09:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-set-for-access-points/m-p/5259590#M594924</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-12T09:36:44Z</dc:date>
    </item>
  </channel>
</rss>

