11-13-2018 12:19 PM - edited 11-13-2018 12:26 PM
I have 2 Rules setup on ACS. Rule-1 is for Radius. Rule-2 is for TACACS.
Authentication Policy for Rule-1 is not going to be exported and giving the following error. All the Authorization policies are being exported though.
Object Type: Policy Groups
==========================================
> 2018.11.13 10:09:57'191 : In Policy Set Rule-1:
Authentication Policy: will not be exported because all of its rules have invalid condition(s) or have not any condition.
Authorization Policy Rule: 'Object_Name': exported successfully.
Rule-2 has no issues and Authentication and Authorization both are being exported:
In Policy Set Rule-2:
Authentication Policy: rule based - exported successfully.
Authorization Policy Rule: 'Object_Name': exported successfully.
How do I fix it?
Solved! Go to Solution.
11-13-2018 11:23 PM
Identity group mapping is not supported on ISE. Please disable it and run the tool again.
11-13-2018 11:23 PM
Identity group mapping is not supported on ISE. Please disable it and run the tool again.
11-14-2018 07:42 AM
Hi Surendra,
Thanks for the reply. Where to disable it? And what about Rule-1 migration if disabling it? Rule-1 is referencing to RADIUS access which is being used and will be required in ISE as well.
Appreciate your guidance. Thanks.
11-14-2018 07:48 AM
11-14-2018 08:06 AM
Hi Surendra,
Thanks for the prompt response. I tried testing it in the lab. It gives the following msg:
So if I remove Group mapping, it will delete the policy and rules. Won't that cause issues in ISE, after the migration?
11-21-2018 06:58 AM
NOT SOLVED YET.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide