<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic ISE policy behavior in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339900#M598598</link>
    <description>&lt;P&gt;One small addition to what Aref said in the last sentence - as mentioned, for MAB Authentication to work, it's required to change the ISE default setting for "User not found" to CONTINUE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1760911604649.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/253857i9869F2102BA29AF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1760911604649.png" alt="ArneBier_0-1760911604649.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to create a final "Catch all" Authorization Rule to process endpoints that ISE sees for the first time (Unknown User), or ones it has seen before but didn't match any AuthZ rules (Not Unknown, but also Auth Passed), you can create a Rule as below&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_1-1760911848777.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/253858iC78D954F076BB5B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_1-1760911848777.png" alt="ArneBier_1-1760911848777.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I don't like using the Default AuthZ rule, because I can't modify the name to reflect the rule's logic - I use a naming convention in my AuthZ rules to filter for things in Live Logs and Context Visibility.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Oct 2025 22:13:31 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-10-19T22:13:31Z</dc:date>
    <item>
      <title>Basic ISE policy behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339607#M598584</link>
      <description>&lt;P&gt;Regarding Authentication, when referencing the Internal Endpoint Database in policy, it seems to me that all profiled nodes will pass authentication since they all get populated into the Endpoint Database upon profiling?&amp;nbsp; If true, the real access control depends on Authorization.&amp;nbsp; In other words, when using MAB, all things (good, bad and ugly) get authenticated, have access to the network and must be stopped or controlled using Authorization?&lt;/P&gt;&lt;P&gt;Can someone please confirm this behavior?&lt;/P&gt;&lt;P&gt;I suppose one could turn off profiling at the expense of its benefits.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 18:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339607#M598584</guid>
      <dc:creator>miller-p</dc:creator>
      <dc:date>2025-10-17T18:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Basic ISE policy behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339674#M598587</link>
      <description>&lt;P&gt;Profiling doesn't play any role here. You're right in saying that any MAC address that is known to ISE would pass authentication when you point to the internal endpoints database but only if that MAC address was seen by ISE. Essentially, if ISE ever stored that MAC address in its internal database and you use that database as the identity source for authentication then yes, authentication for that device will pass and the decision will happen based on the authorization policy. Inother interesting use case would be with guest users. The guest endpoints usually are not managed by ISE and they come to ISE as new endpoints, so ISE wouldn't have any of those endpoints MAC addresses stored in its database. So, to allow them access to their isolated network we change a setting in the authentication rule saying if the authentication fails consider it as passed anyway. In simple words we're telling ISE don't worry about if you know that MAC or not, just pass it, and then we enforce the access of those guests on the authorization rules. You could add a condition in the authorization rule to check if the authentication has passed, but that won't change much because if the MAC is already known to ISE it means it has passed the authentication.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Oct 2025 08:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339674#M598587</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-10-18T08:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Basic ISE policy behavior</title>
      <link>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339900#M598598</link>
      <description>&lt;P&gt;One small addition to what Aref said in the last sentence - as mentioned, for MAB Authentication to work, it's required to change the ISE default setting for "User not found" to CONTINUE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1760911604649.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/253857i9869F2102BA29AF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1760911604649.png" alt="ArneBier_0-1760911604649.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to create a final "Catch all" Authorization Rule to process endpoints that ISE sees for the first time (Unknown User), or ones it has seen before but didn't match any AuthZ rules (Not Unknown, but also Auth Passed), you can create a Rule as below&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_1-1760911848777.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/253858iC78D954F076BB5B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_1-1760911848777.png" alt="ArneBier_1-1760911848777.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I don't like using the Default AuthZ rule, because I can't modify the name to reflect the rule's logic - I use a naming convention in my AuthZ rules to filter for things in Live Logs and Context Visibility.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Oct 2025 22:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/basic-ise-policy-behavior/m-p/5339900#M598598</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-10-19T22:13:31Z</dc:date>
    </item>
  </channel>
</rss>

