<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nice username! :)So yes, you in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503310#M89338</link>
    <description>&lt;P&gt;Nice username! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So yes, you are correct, the logical profiles would allow you to group different type of dynamically profiled devices and then reference that profile in your&amp;nbsp;&lt;STRONG&gt;authorization&amp;nbsp;&lt;/STRONG&gt;rules. However, you won't see those logical profiles under the "Identity Group Details" section. You will need to leave that field blank. Instead, you need to look in the "second" condition box:&amp;nbsp;&lt;STRONG&gt;expression &amp;gt; Endpoint &amp;gt; LogicalProfile&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2014 08:32:41 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2014-07-29T08:32:41Z</dc:date>
    <item>
      <title>Logical Profiles in ISE 1.2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503309#M89337</link>
      <description>&lt;P&gt;I´m having trouble understanding the Logical Profiles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I understand from the user guide:&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html#58510" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html#58510&lt;/A&gt;&lt;/P&gt;&lt;P&gt;for those to lazy to read:&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use the logical profile in an authorization policy condition to help create an overall network access policy for a category of profiles. You can create a simple condition for authorization, which can be included in the authorization rule. The attribute-value pair that you can use in the authorization condition is the logical profile (attribute) and the name of the logical profile (value), which can be found in the EndPoints systems dictionary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I thought that meant that I can group Different Profiles (Apple Iphone, Ipad, Ipod) together into a logical group e.g. "BYOD_Idevice" and use this logical profile in the Authorization.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I can´t choose this freshly created Logical Group in the Authorization Condition. As for the fact, I can´t choose this logical group ANYWHERE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Leaning back and thinking about it - it somehow makes sense. In the Authorization, you don´t pick Profiles, you choose Identity endpoints. So whats the point about the logical profiles? I was hoping to clean/lean up my authorization rules with them. But for what would I use them else?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is this a bug in ise 1.2.1? Not sure if I should call tac about this, or if I´m just not getting it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks alot for your help! &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503309#M89337</guid>
      <dc:creator>MeMySelfundCisco</dc:creator>
      <dc:date>2019-03-11T04:53:43Z</dc:date>
    </item>
    <item>
      <title>Nice username! :)So yes, you</title>
      <link>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503310#M89338</link>
      <description>&lt;P&gt;Nice username! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So yes, you are correct, the logical profiles would allow you to group different type of dynamically profiled devices and then reference that profile in your&amp;nbsp;&lt;STRONG&gt;authorization&amp;nbsp;&lt;/STRONG&gt;rules. However, you won't see those logical profiles under the "Identity Group Details" section. You will need to leave that field blank. Instead, you need to look in the "second" condition box:&amp;nbsp;&lt;STRONG&gt;expression &amp;gt; Endpoint &amp;gt; LogicalProfile&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 08:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503310#M89338</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-07-29T08:32:41Z</dc:date>
    </item>
    <item>
      <title>AWESOME! it works! How cool</title>
      <link>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503311#M89339</link>
      <description>&lt;P&gt;AWESOME!&amp;nbsp;&lt;/P&gt;&lt;P&gt;it works! How cool is that. O.k a bit complicated, but what the heck. it works! thanks alot for your help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 09:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503311#M89339</guid>
      <dc:creator>MeMySelfundCisco</dc:creator>
      <dc:date>2014-07-29T09:34:29Z</dc:date>
    </item>
    <item>
      <title>No problem! Glad I could help</title>
      <link>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503312#M89341</link>
      <description>&lt;P&gt;No problem! Glad I could help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 16:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logical-profiles-in-ise-1-2-1/m-p/2503312#M89341</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-07-29T16:16:30Z</dc:date>
    </item>
  </channel>
</rss>

