<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IBNS2.0 Cannot nest class-map in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ibns2-0-cannot-nest-class-map/m-p/4459576#M1083320</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to do the following :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;&amp;nbsp; &amp;nbsp;sgt 3&lt;BR /&gt;&amp;nbsp; &amp;nbsp;vlan 100&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;class-map type control subscriber match-all AAA_SVR_DOWN_UNAUTHD_IOT_DEVICES&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match result-type aaa-timeout&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match authorization-status unauthorized&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match ---&amp;gt;&amp;gt;&amp;gt; &lt;FONT color="#FF0000"&gt;I would like to match a list of MAC OUI here but I can't since the "match-all" condition is set and I need it &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/FONT&gt;&lt;BR /&gt;!&lt;BR /&gt;class-map type control subscriber match-any IN_LOCAL_AUTH_MODE&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match activated-service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;!&lt;BR /&gt;policy-map type control subscriber PMAP_DefaultWiredDot1xClosedAuth_1X_MAB&lt;/P&gt;&lt;P&gt;....&lt;BR /&gt;&amp;nbsp; &amp;nbsp; event authentication-failure match-first&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6 class&amp;nbsp;AAA_SVR_DOWN_UNAUTHD_IOT_DEVICES do-until-failure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10 activate service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 30 authorize&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 40 pause reauthentication&lt;BR /&gt;&amp;nbsp; &amp;nbsp; event aaa-available match-all&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30 class IN_LOCAL_AUTH_MODE do-until-failure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10 clear-session&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;Basically I need to nest a class-map with a match-any condition inside a class-map with a match-all condition..&lt;/P&gt;&lt;P&gt;This seems not be supported so do someone has a good alternative to this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to avoid creating one class-map per OUI family&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 18:17:03 GMT</pubDate>
    <dc:creator>rlienard</dc:creator>
    <dc:date>2021-09-03T18:17:03Z</dc:date>
    <item>
      <title>IBNS2.0 Cannot nest class-map</title>
      <link>https://community.cisco.com/t5/network-security/ibns2-0-cannot-nest-class-map/m-p/4459576#M1083320</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to do the following :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;&amp;nbsp; &amp;nbsp;sgt 3&lt;BR /&gt;&amp;nbsp; &amp;nbsp;vlan 100&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;class-map type control subscriber match-all AAA_SVR_DOWN_UNAUTHD_IOT_DEVICES&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match result-type aaa-timeout&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match authorization-status unauthorized&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match ---&amp;gt;&amp;gt;&amp;gt; &lt;FONT color="#FF0000"&gt;I would like to match a list of MAC OUI here but I can't since the "match-all" condition is set and I need it &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/FONT&gt;&lt;BR /&gt;!&lt;BR /&gt;class-map type control subscriber match-any IN_LOCAL_AUTH_MODE&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match activated-service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;!&lt;BR /&gt;policy-map type control subscriber PMAP_DefaultWiredDot1xClosedAuth_1X_MAB&lt;/P&gt;&lt;P&gt;....&lt;BR /&gt;&amp;nbsp; &amp;nbsp; event authentication-failure match-first&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6 class&amp;nbsp;AAA_SVR_DOWN_UNAUTHD_IOT_DEVICES do-until-failure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10 activate service-template IOT_DEVICES_TEMPLATE&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 30 authorize&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 40 pause reauthentication&lt;BR /&gt;&amp;nbsp; &amp;nbsp; event aaa-available match-all&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30 class IN_LOCAL_AUTH_MODE do-until-failure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10 clear-session&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;Basically I need to nest a class-map with a match-any condition inside a class-map with a match-all condition..&lt;/P&gt;&lt;P&gt;This seems not be supported so do someone has a good alternative to this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to avoid creating one class-map per OUI family&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 18:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ibns2-0-cannot-nest-class-map/m-p/4459576#M1083320</guid>
      <dc:creator>rlienard</dc:creator>
      <dc:date>2021-09-03T18:17:03Z</dc:date>
    </item>
  </channel>
</rss>

