<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE configuration no internet access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849183#M1101258</link>
    <description>&lt;P&gt;Which Authorization Profile should it be hitting?&amp;nbsp;&lt;BR /&gt;It is hitting the Endpoint ID group, but within the Profile set it is hitting default. I assume because there is no relevant Auth Profile with the BYOD User MAB&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2023 12:01:08 GMT</pubDate>
    <dc:creator>IanTonyBirchall</dc:creator>
    <dc:date>2023-06-06T12:01:08Z</dc:date>
    <item>
      <title>Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849060#M1101254</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have been stuck for several days on an ISE authentication problem with SAML.&lt;/P&gt;&lt;P&gt;Microsoft authentication works fine then the ISE redirects to google.com and it fails to change the authorization profile. As he does not have Internet access with the basic ACL he returns to Microsoft authentication.&lt;/P&gt;&lt;P&gt;It does add my MAC address in the group: EIG_BYODEndpoints&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jldebelder1984_0-1686045690123.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186579iE055863EB8BC4515/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jldebelder1984_0-1686045690123.png" alt="jldebelder1984_0-1686045690123.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jldebelder1984_2-1686045882817.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186583iBC0F0372F9C5A165/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jldebelder1984_2-1686045882817.png" alt="jldebelder1984_2-1686045882817.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;my authorization profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jldebelder1984_3-1686045940136.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186587iB2D227127A0D923D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jldebelder1984_3-1686045940136.png" alt="jldebelder1984_3-1686045940136.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I cut my wifi and restart my connection, I have internet access directly without going through SAML authentication.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jldebelder1984_4-1686045989811.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186588i8B4765B14FF2B490/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jldebelder1984_4-1686045989811.png" alt="jldebelder1984_4-1686045989811.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 10:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849060#M1101254</guid>
      <dc:creator>jldebelder1984</dc:creator>
      <dc:date>2023-06-06T10:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849183#M1101258</link>
      <description>&lt;P&gt;Which Authorization Profile should it be hitting?&amp;nbsp;&lt;BR /&gt;It is hitting the Endpoint ID group, but within the Profile set it is hitting default. I assume because there is no relevant Auth Profile with the BYOD User MAB&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 12:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849183#M1101258</guid>
      <dc:creator>IanTonyBirchall</dc:creator>
      <dc:date>2023-06-06T12:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849219#M1101263</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;BR /&gt;With the default because it's his first connection.&lt;/P&gt;&lt;P&gt;What's weird is that when I log back &amp;nbsp;in (&lt;SPAN&gt;after turning off wifi)&amp;nbsp;&lt;/SPAN&gt;then it matches with "BYOD USER MAB".&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 13:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849219#M1101263</guid>
      <dc:creator>jldebelder1984</dc:creator>
      <dc:date>2023-06-06T13:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849223#M1101265</link>
      <description>&lt;P&gt;After the SAML validation, he adds the mac address in the group but he can't match in the first &lt;SPAN&gt;Authorization Profile&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 13:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849223#M1101265</guid>
      <dc:creator>jldebelder1984</dc:creator>
      <dc:date>2023-06-06T13:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849263#M1101272</link>
      <description>&lt;P&gt;If I am right, the First condition will match MACs in the EIG_BYODEnpoints So that make sense that the authorization is BYOD User MAB.&amp;nbsp;&lt;BR /&gt;So the problem is with SAML validation, it should be achieving the same as the MAC is detailed and should be captured within the endpoints correct?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 14:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849263#M1101272</guid>
      <dc:creator>IanTonyBirchall</dc:creator>
      <dc:date>2023-06-06T14:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE configuration no internet access</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849919#M1101294</link>
      <description>&lt;P&gt;Yes that's right.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 07:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-configuration-no-internet-access/m-p/4849919#M1101294</guid>
      <dc:creator>jldebelder1984</dc:creator>
      <dc:date>2023-06-07T07:59:00Z</dc:date>
    </item>
  </channel>
</rss>

