<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE policy using ip subnet for authorisation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307286#M597161</link>
    <description>&lt;P&gt;Hello we are usinh 9120 AP's&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jul 2025 09:31:51 GMT</pubDate>
    <dc:creator>guy.whitehouse@ft.com</dc:creator>
    <dc:date>2025-07-09T09:31:51Z</dc:date>
    <item>
      <title>ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307259#M597158</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;We are running flexconnect wifi and using the same ssid across multiple sites.&lt;/P&gt;&lt;P&gt;We want to deploy a splash page at each flexconnect remote site for one of our ssid's&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not want to deploy all sites at the same time&lt;/P&gt;&lt;P&gt;So is it possible to authenticate against a ip subnet ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we could say if the request comes from subnet x to ise please provide a splash page&lt;/P&gt;&lt;P&gt;Or is their another way we could do this&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 08:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307259#M597158</guid>
      <dc:creator>guy.whitehouse@ft.com</dc:creator>
      <dc:date>2025-07-09T08:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307281#M597159</link>
      <description>&lt;P&gt;With Flexconnect, the RADIUS Access-Request comes from the WLC (central authentication) and not from the WAP itself (which means we can't regard the IP address of the WAP) - if my recollection of how this works is still correct, then it will be hard to localise which site/WAP the request is coming from. The Called-Station-ID attribute in the Access-Request can be constructed to contain SSID and MAC address of the WAP involved - but that means your ISE Wireless MAB Authorization Policy would need a complex condition to check for all the MAC addresses involved - depending on your deployment, that might be infeasible.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1752052550191.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/247931i198E7A7DEE1007EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1752052550191.png" alt="ArneBier_0-1752052550191.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The MAC addresses shown above use dashes as delimiter - best to validate this in wireshark via tcpdump.&lt;/P&gt;
&lt;P&gt;If you can share a wireshark decode of a flexconnect Access-Request that shows all the attributes, perhaps there is a better one to use that would work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 09:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307281#M597159</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-07-09T09:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307283#M597160</link>
      <description>&lt;P&gt;Sure Yes if wlc + AP add IP of wifi to radius request&lt;/P&gt;
&lt;P&gt;Can I know the wlc or AP you use?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 09:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307283#M597160</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-09T09:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307286#M597161</link>
      <description>&lt;P&gt;Hello we are usinh 9120 AP's&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 09:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307286#M597161</guid>
      <dc:creator>guy.whitehouse@ft.com</dc:creator>
      <dc:date>2025-07-09T09:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307292#M597162</link>
      <description>&lt;P&gt;The model of AP/WLC is neither here nor there. The question to answer is what the RADIUS Access-Request looks like when an endpoint (client device) associates to the SSID on such a FlexConnect WAP.&amp;nbsp; My theory about the Called-Station-ID might be correct, but as mentioned, it's probably not feasible if there are many WAPs involved.&lt;/P&gt;
&lt;P&gt;The Framed-IP-Address could also be used - this is the IP address of the end client - but ISE only supports EQUALS and NOT EQUALS operators - which means you can't write a regular expression to match an entire subnet (we need the MATCHES operator) - I don't think you want to write an ISE OR condition that contains all the IP addresses in a potentially large subnet.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 09:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307292#M597162</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-07-09T09:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307306#M597163</link>
      <description>&lt;P&gt;You mentioned flexcon so what is wlc plat you?&lt;/P&gt;
&lt;P&gt;Did yoh try use calling-station-ID type ip-add?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 10:42:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307306#M597163</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-09T10:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307341#M597166</link>
      <description>&lt;P&gt;I usually do this by setting called-station-id to "ap-name-ssid" and matching based on AP name. This is easier to understand for colleagues working with the ISE deployment and the AP name prefix is usually equally if not more suited to match the specific site.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307341#M597166</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-07-09T11:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307347#M597168</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We are using 5520 WLC&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307347#M597168</guid>
      <dc:creator>guy.whitehouse@ft.com</dc:creator>
      <dc:date>2025-07-09T12:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy using ip subnet for authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307365#M597170</link>
      <description>&lt;P&gt;Calling-station-id ""wifi endpoint info""&lt;/P&gt;
&lt;P&gt;Called-station-id ""AP""&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-using-ip-subnet-for-authorisation/m-p/5307365#M597170</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-09T12:37:52Z</dc:date>
    </item>
  </channel>
</rss>

