cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
543
Views
0
Helpful
2
Replies

2.2 to 2.4 Authentication Policy

latenaite2011
Level 4
Level 4

Does anyone know how to create the authentication policy in 2.4 of the equivalent authentication policy of 2.2 attached?

 

I am having problem trying to have both the allowed protocols of HOST_LOOKUP (or any protocol that is selected) and "internal endpoints" using the same rule and you will see there there is also a default keyword under MAB so I am confused.

 

This MAB authentication policy is under the machine authentication policy LM_WIRED...

 

When you review the details of the log, you will see the authentication policy as

 

LM WIRED  ---> MAB --->> Default -->

 

 

2 Replies 2

Arne Bier
VIP
VIP

Does this work for you?

 

LM-wired1.PNG

I used the built-in smart condition called Wired_MAB because it's useful and adapts dynamically to other vendor implementations - see below

 

LM-wired2.PNG

 

And then the rest of the Policy Set would look like this (not sure whether you want to tell ISE to Continue if User not found?  And also, what is your Authorization Policy ?  I just made something up that will send Access-Accept if Authentication passed)

LM-wired3.PNG

 

 

 

 

Arne Bier
VIP
VIP

Does this work for you?

 

LM-wired1.PNG

I used the built-in smart condition called Wired_MAB because it's useful and adapts dynamically to other vendor implementations - see below

 

LM-wired2.PNG

 

And then the rest of the Policy Set would look like this (not sure whether you want to tell ISE to Continue if User not found?  And also, what is your Authorization Pol

LM-wired3.PNG