<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Policy getting wrongly selected in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570149#M601059</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750896"&gt;@md-shahnawaz&lt;/a&gt;&amp;nbsp;the connection is probably still not matching the correct authorisation rule, so does not get the posture redirect, thus not detecting the policy server. You need to ensure the connection request matches the correct rule.&lt;/P&gt;
&lt;P&gt;Provide a screenshot of your authorisation rules and the output of the live log of your connection event and we can help.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2026 10:41:44 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2026-08-19T10:41:44Z</dc:date>
    <item>
      <title>Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569908#M601049</link>
      <description>&lt;P&gt;Hello All.&lt;/P&gt;&lt;P&gt;i am using LAN to connect in my office, I am seeing my secure vpn client network is on wired, ISE posture status is also showing complaint (network access allowed) but on ISE I am seeing I am hitting to Wi-Fi policy instead of wired policy and ISE logs also show i am complaint.&lt;/P&gt;&lt;P&gt;I am not able to understand why i am not hitting to wireless ISE policy if I am on wired, I checked logs for my team and their profile is correctly updated. please suggest what i need to check to fix this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 07:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569908#M601049</guid>
      <dc:creator>md-shahnawaz</dc:creator>
      <dc:date>2026-08-18T07:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569911#M601050</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750896"&gt;@md-shahnawaz&lt;/a&gt;&amp;nbsp;it is probably the conditions you are using in your authorisation policy need tweaking, to ensure the correct connection method matches the correct rule.&lt;/P&gt;
&lt;P&gt;Please provide screenshot of your authorisation rules, and indicate what rules the connection is matching and should match.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 07:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569911#M601050</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-08-18T07:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569970#M601051</link>
      <description>&lt;P&gt;I would also maybe look at your policy sets and break them out by type to make rules easier to read and follow.&lt;/P&gt;
&lt;P&gt;Thus is how ours is set.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-08-18 082813.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/285794iA079F96A6EE7D325/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-08-18 082813.jpg" alt="Screenshot 2026-08-18 082813.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 13:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5569970#M601051</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2026-08-18T13:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570034#M601052</link>
      <description>&lt;P&gt;dear&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750896"&gt;@md-shahnawaz&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;# Open Operations &amp;gt; RADIUS &amp;gt; Live Logs, &lt;BR /&gt;select the affected authentication, &lt;BR /&gt;and check the detailed authentication report &amp;amp;&amp;nbsp;attributes &amp;gt;&amp;gt;&lt;BR /&gt;&amp;gt;&amp;gt; NAS-Port-Type ??&lt;BR /&gt;&amp;gt;&amp;gt; NAS-Port-ID ??&lt;BR /&gt;&amp;gt;&amp;gt; NetworkDeviceName ??&lt;BR /&gt;&amp;gt;&amp;gt; Service-Type ??&lt;BR /&gt;&amp;gt;&amp;gt; Called-Station-ID ??&lt;BR /&gt;&amp;gt;&amp;gt; SSID attributes, if present.. ??&lt;BR /&gt;&amp;gt;&amp;gt; The exact Policy Set condition that matched ??&lt;BR /&gt;&lt;BR /&gt;Make sure the Wi-Fi Policy Set is not using overly broad conditions and is not placed above the wired Policy Set in a way that also matches wired requests.&lt;BR /&gt;&lt;BR /&gt;Verify that the wired switch is assigned to the correct Network Device Group in ISE.&lt;BR /&gt;&lt;BR /&gt;Check the switch AAA/RADIUS and interface configuration to confirm that it sends the correct NAS-Port-Type.&lt;BR /&gt;&lt;BR /&gt;If policy selection depends on endpoint profiling, verify that the endpoint does not have a stale or incorrectly assigned profile. Delete/reprofile the endpoint only if necessary.&lt;BR /&gt;&lt;BR /&gt;Compare the full RADIUS attributes of this endpoint with another wired endpoint that selects the correct policy..&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 20:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570034#M601052</guid>
      <dc:creator>Mohammadreza Hadi</dc:creator>
      <dc:date>2026-08-18T20:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570145#M601057</link>
      <description>&lt;P&gt;hello Rob&lt;/P&gt;&lt;P&gt;thank you for your inputs, now after restarting i am seeing posture status is showing no policy server detected and default network access is in effect, on ISE logs could see I am hitting to Wi-Fi policy whereas I am on LAN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mdshahnawaz_0-1787135081427.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/285844iE1AE1785E4C01983/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mdshahnawaz_0-1787135081427.png" alt="mdshahnawaz_0-1787135081427.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 10:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570145#M601057</guid>
      <dc:creator>md-shahnawaz</dc:creator>
      <dc:date>2026-08-19T10:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570148#M601058</link>
      <description>&lt;P&gt;Hello Dustin, issue which i am suspecting is secure client is not able to detect the PSN nodes and getting stuck in posture redirect policy and its not moving further. i am not sure where and what to check?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 10:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570148#M601058</guid>
      <dc:creator>md-shahnawaz</dc:creator>
      <dc:date>2026-08-19T10:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570149#M601059</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750896"&gt;@md-shahnawaz&lt;/a&gt;&amp;nbsp;the connection is probably still not matching the correct authorisation rule, so does not get the posture redirect, thus not detecting the policy server. You need to ensure the connection request matches the correct rule.&lt;/P&gt;
&lt;P&gt;Provide a screenshot of your authorisation rules and the output of the live log of your connection event and we can help.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 10:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570149#M601059</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-08-19T10:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Policy getting wrongly selected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570184#M601062</link>
      <description>&lt;P&gt;It would depend how your rules are set and if it's too vague if that makes sense. You usually want them in order so compliant user would be before the redirect. Redirect would usually be for non-compliant or unknown status.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, do you check status every connection, or does it remember compliant status for a while? When we use to do it we had it remember for a week.&lt;/P&gt;
&lt;P&gt;For check in, make sure the device can talk to the PSN on port 8905.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 13:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-policy-getting-wrongly-selected/m-p/5570184#M601062</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2026-08-19T13:16:00Z</dc:date>
    </item>
  </channel>
</rss>

