<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE LDAP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267596#M920710</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same effect. The ISE said "Authentication failed : 15039 Rejected per authorization profile".&lt;/P&gt;&lt;P&gt;I tried 3 groups without success.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Jun 2013 08:38:50 GMT</pubDate>
    <dc:creator>Marco Serato</dc:creator>
    <dc:date>2013-06-26T08:38:50Z</dc:date>
    <item>
      <title>Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267592#M920706</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´ve got a problem with the authorization to use a condition with an External Group from the LDAP.&lt;/P&gt;&lt;P&gt;I bind the LDAP-Server to the ISE and can select all groups that I need for my authorization condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to create an authorization profile with the use of the group “Admins”.&lt;/P&gt;&lt;P&gt;My policy looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LDAP: ExternalGroups EQUALS CN=Admins,DC=mydomain,DC=com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The live monitor said every time reject by authorization profile. If I use NOT EQUALS, then the computer get access to the network. It is very confused, because the computer is a member of the group “Admins”.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267592#M920706</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2020-02-21T12:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267593#M920707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've seen issues while selecting LDAP as an external db with condition/attribute as ExternalGroups. Could you please go to live authentication , clcik on the magnifying glass and paste the details of failed attempt. I would like to know if this group is coming up in the memberOf attributes for the user. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 08:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267593#M920707</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-18T08:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267594#M920708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The appendix is an excerpt. I used the group "domain computers" for test. But I can´t see the group in the attributtes.&lt;/P&gt;&lt;P&gt;I hope it is helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;In the appendix are some missing. Here are the Other Attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MTU=1500,CPMSessionID=AC1C01C7000000040022D940,EndPointMACAddress=93-9A-88-AD-18-EE,Device Type=Device Type#All Device Types,Location=Location#All Locations,Device IP Address=192.168.178.254,Called-Station-ID=02:81:D0:11:EC:31&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 07:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267594#M920708</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2013-06-19T07:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267595#M920709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since it's not coming in authentication request there is no way the condition will get matched. Please don't use domain computers group for user authentication. Could you please assign user a different group like domain admins and test again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 12:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267595#M920709</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-20T12:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267596#M920710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same effect. The ISE said "Authentication failed : 15039 Rejected per authorization profile".&lt;/P&gt;&lt;P&gt;I tried 3 groups without success.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 08:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267596#M920710</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2013-06-26T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267597#M920711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post screenshot of your authorization rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 16:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267597#M920711</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2013-07-01T16:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267598#M920712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here the screenshot&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/7/2/144279-Authorization%20Policy.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 07:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267598#M920712</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2013-07-03T07:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE LDAP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267599#M920713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anybody an idea? The problem still exists. &lt;/P&gt;&lt;P&gt;I have bind the LDAP add groups from directory once again. But the same effect. &lt;/P&gt;&lt;P&gt;If I use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LDAP:ExternalGroups Equals CN=domain computers,OU=computer, DC=mydomain,DC=com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mycomputer get no network access. Without this condition I get full access. I despair of this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 14:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ise-ldap/m-p/2267599#M920713</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2013-08-28T14:32:44Z</dc:date>
    </item>
  </channel>
</rss>

