<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE  - hitting wrong NetworkDevice Group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5313034#M597441</link>
    <description>&lt;P&gt;I check cisco doc and other notes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device profile not send as radius attribute so ISE can&amp;nbsp; not use it to identify device.&lt;/P&gt;
&lt;P&gt;Retrun to IP conflict'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE support range of IP so you can use range of IP to exclude single device IP from device group&lt;/P&gt;
&lt;P&gt;I.e. 10.0.0.100/32 single&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.0.0.0/24 device group&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In ISE add IP for device group as&lt;/P&gt;
&lt;P&gt;10.0.0.1-10.0.0.99&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.0.0.101-10.0.0.254&lt;/P&gt;
&lt;P&gt;Hope this help you to solve problem&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2025 16:40:57 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-07-23T16:40:57Z</dc:date>
    <item>
      <title>Cisco ISE  - hitting wrong NetworkDevice Group</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312058#M597410</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;For some reason, an authentication request for node 172.23.140.200&amp;nbsp;is hitting the wrong Network Devices Group, though there is a long prefix/32 available. Consequently, the wrong Policy-Set is chosen with Privilege Level1.&lt;/P&gt;&lt;P&gt;Usually ISE is expected to hit the longest prefix&lt;/P&gt;&lt;P&gt;#1 Arista_mgmt: &lt;STRONG&gt;172.23.140.200/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#6: Private-172-Network1:&amp;nbsp; &lt;STRONG&gt;172.23.128.0/20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Netmart_0-1753135433086.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248754iBACEA800D8AAED82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Netmart_0-1753135433086.png" alt="Netmart_0-1753135433086.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jun 19 17:27:22 ISE-1 CISE_Passed_Authentications 0485078549 4 0 2025-06-19 17:27:22.220 -04:00 59105442473 5201&lt;/P&gt;&lt;P&gt;NOTICE Passed-Authentication: Authentication succeeded, ConfigVersionId=71, &lt;STRONG&gt;Device IP Address=172.23.140.200, &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DestinationIPAddress=******, DestinationPort=49, UserName=cvpadmin, Protocol=Tacacs, &lt;STRONG&gt;NetworkDeviceName&lt;/STRONG&gt;&lt;STRONG&gt;=Private-172-Network1&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;Type=Authentication, Action=Login, &lt;STRONG&gt;Privilege-Level=1,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Version:&lt;/DIV&gt;&lt;DIV class=""&gt;3.1.0.518&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Patch Information:&amp;nbsp;3&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Any advice is much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 22:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312058#M597410</guid>
      <dc:creator>Netmart</dc:creator>
      <dc:date>2025-07-21T22:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE  - hitting wrong NetworkDevice Group</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312524#M597416</link>
      <description>&lt;P&gt;3.1 patch 3 is very old at this point. I would not spend any time troubleshooting this issue until you upgrade to the latest 3.1 patch.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/identity-service-engine-software-3-1-3-2.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/identity-service-engine-software-3-1-3-2.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 19:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312524#M597416</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-07-22T19:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE  - hitting wrong NetworkDevice Group</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312530#M597417</link>
      <description>&lt;P&gt;Did you try change device profile under network device list ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 20:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5312530#M597417</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-22T20:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE  - hitting wrong NetworkDevice Group</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5313012#M597440</link>
      <description>&lt;P&gt;Thank you MHM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Work Centers &amp;gt; Network Access &amp;gt; Network Devices: the IP is listed under Network Devices List.&lt;/P&gt;&lt;P&gt;I would appreciate, if you could please guide me where the device profile is linked to the network device list.&lt;/P&gt;&lt;P&gt;Please keep in mind that other IPs in the same Network Device List are hitting the proper policy [based on the logs].&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 16:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5313012#M597440</guid>
      <dc:creator>Netmart</dc:creator>
      <dc:date>2025-07-23T16:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE  - hitting wrong NetworkDevice Group</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5313034#M597441</link>
      <description>&lt;P&gt;I check cisco doc and other notes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device profile not send as radius attribute so ISE can&amp;nbsp; not use it to identify device.&lt;/P&gt;
&lt;P&gt;Retrun to IP conflict'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE support range of IP so you can use range of IP to exclude single device IP from device group&lt;/P&gt;
&lt;P&gt;I.e. 10.0.0.100/32 single&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.0.0.0/24 device group&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In ISE add IP for device group as&lt;/P&gt;
&lt;P&gt;10.0.0.1-10.0.0.99&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.0.0.101-10.0.0.254&lt;/P&gt;
&lt;P&gt;Hope this help you to solve problem&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 16:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-hitting-wrong-networkdevice-group/m-p/5313034#M597441</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-23T16:40:57Z</dc:date>
    </item>
  </channel>
</rss>

