<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to setup wireless MAB using a specific group/list on ISE? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451337#M232450</link>
    <description>&lt;P&gt;Hi, pretty new to this so please be gentle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a WLC that we setup for wireless Mac authentication on the local WLC database. I want to move this list of mac addresses to ISE. I am following a tutorial which says to create an endpoint identity group and add the mac addresses to that (I called it "IOT_Halls").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fine, however when I create the authentication policy (see attached) it doesn't contain the "IOT_Halls" identity group in the "use" drop down menu. Now the tutorial does say to use the "Internal Endpoints" option in the dropdown however I only want to use the mac addresses on the "IOT_Halls" list I created. I also don't understand what or where "Internal Endpoints" are/is? Finally, we have another policy that already uses "Internal Endpoints" (setup before my time) so this must contain mac addresses I don't want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess the two questions are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is&amp;nbsp;"Internal Endpoints" and where is this located in ISE?&lt;/P&gt;&lt;P&gt;- How do I use only the IOT_Halls list of Mac addresses in my authentication policy and not every 'internal endpoint'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks, very much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Aug 2021 16:33:22 GMT</pubDate>
    <dc:creator>Mottok</dc:creator>
    <dc:date>2021-08-18T16:33:22Z</dc:date>
    <item>
      <title>How to setup wireless MAB using a specific group/list on ISE?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451337#M232450</link>
      <description>&lt;P&gt;Hi, pretty new to this so please be gentle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a WLC that we setup for wireless Mac authentication on the local WLC database. I want to move this list of mac addresses to ISE. I am following a tutorial which says to create an endpoint identity group and add the mac addresses to that (I called it "IOT_Halls").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fine, however when I create the authentication policy (see attached) it doesn't contain the "IOT_Halls" identity group in the "use" drop down menu. Now the tutorial does say to use the "Internal Endpoints" option in the dropdown however I only want to use the mac addresses on the "IOT_Halls" list I created. I also don't understand what or where "Internal Endpoints" are/is? Finally, we have another policy that already uses "Internal Endpoints" (setup before my time) so this must contain mac addresses I don't want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess the two questions are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is&amp;nbsp;"Internal Endpoints" and where is this located in ISE?&lt;/P&gt;&lt;P&gt;- How do I use only the IOT_Halls list of Mac addresses in my authentication policy and not every 'internal endpoint'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks, very much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 16:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451337#M232450</guid>
      <dc:creator>Mottok</dc:creator>
      <dc:date>2021-08-18T16:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup wireless MAB using a specific group/list on ISE?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451485#M232462</link>
      <description>&lt;P&gt;From the image, you are on the starting policy page? Here you only set an allowed protocol for MAB, I believe you will then want to call the group you made in the rules under this section. We use&amp;nbsp; AD groups for MAB, but should be similar.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 21:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451485#M232462</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2021-08-18T21:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup wireless MAB using a specific group/list on ISE?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451504#M232463</link>
      <description>&lt;P&gt;Many thanks for your reply, I think I'm getting there I think.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I've setup a protocol called 'MAB' (see 'PolicySet' attached) as you suggested which allows the host lookup. I have conditions set to look for requests coming from the WLC and only on WLANID 6, can I ask what your condition named "Wireless MAB" actually looks for and I suppose how it is different from mine (other than the WLANID 6 bit obviously)?&lt;BR /&gt;&lt;BR /&gt;I've managed to finally point to the IOT_halls group in the Authorisation policy (see attached) but had a question about the column labelled "Security Groups", what is this used for if I'm already pointing to a group? Is it needed at all?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 10:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451504#M232463</guid>
      <dc:creator>Mottok</dc:creator>
      <dc:date>2021-08-19T10:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup wireless MAB using a specific group/list on ISE?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451903#M232504</link>
      <description>&lt;P&gt;So, the wireless MAB is just the default ISE rule. We use the auth policy rules to do the breakout. I would think where we call AD, you could check your group. You may need to just call MAB in the main policy, not sure if it will only take it as 802.1x otherwise. Probably many ways to try it. For wireless, we have 1 SSID for MAB, but break out based on 4 different groups and by location it's coming from and the vlans are different.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 14:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4451903#M232504</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2021-08-19T14:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup wireless MAB using a specific group/list on ISE?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4452312#M232529</link>
      <description>&lt;P&gt;Thank you very much that's been really useful. Especially as I wouldn't have included the correct allowed protocol (MAB) as the tutorial I was looking at was from the older version of ISE and a little confusing when translating over to the newer version. I am ready to test on Monday and will pop a note to say how it goes. Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 08:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-setup-wireless-mab-using-a-specific-group-list-on-ise/m-p/4452312#M232529</guid>
      <dc:creator>Mottok</dc:creator>
      <dc:date>2021-08-20T08:52:06Z</dc:date>
    </item>
  </channel>
</rss>

