09-11-2017 10:50 AM
Okay this will be a little venting of a post, but want to ask about a few issues in reporting on ISE authentication activity. In our best practices we have the following:
With this naming convention, we can hide the Authentication Policy and Authorization Policy in the Live Log window as they are irrelevant. The Authorization Profile column tells the user exactly what happened. The Authorization Profile is the result applied to the user and what is important. The rule name is irrelevant, although we name them accordingly.
In ISE 2.1, I identified a bug (CSCvb46991) in the Context Visibility screen where the Authorization Profile column was putting the rule name in by mistake. It seems like the solution for that bug was to get rid of the Authorization Profile column all together. So instead of fixing the issue, the ability to filter on our well name results isn't an option on the Context Visibility screen.
In the RADIUS authentication reports, you can add the "AZN Policy" (this is a 1.0 name I think... why hasn't this been updated), but you can't filter on that column. Makes no sense why you can't filter on any of the columns.
Any reasons we can't use Authorization Profiles as filtering conditions in Context Visibility and Reports? It looks silly to customers when they have well named results and they can't use them on all screens when in my mind there is no difficult technical reason behind it.
Solved! Go to Solution.
09-13-2017 10:31 PM
CSCvf95756 opened on the request to allow filtering on Authorization Profiles.
As part of CSCvb46991, we found in ISE 2.1
that the column "Authorization Profile" displaying "Authorization Policy (rule name)" and
that the column "SelectedAuthorizationProfiles" mapping to "Authorization Profiles".
The fix corrected the column/field names:
Authorization Policy --> Authentication Policy (rule name)
Authorization Profile --> Authorization Policy (rule name)
09-11-2017 12:06 PM
Yes, it is odd that AuthZ Profile removed, but you can add it back by creating a new view with the Authentication attributes set and adding the SelectedAuthorizationProfiles attribute. I will copy PM on visibility on this post.
09-11-2017 12:11 PM
Ahh thanks for that tip Craig. Never thought about creating a new view. If the AZN Policy column was searchable in reports then we would be back in business.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
09-12-2017 10:14 AM
Did you mean AZN profiles instead of AZN policy as the latter implies Authorization rule and can already be filtered?
09-12-2017 10:19 AM
Authorization rule is the rule name not the applied Authorization Policy. I should be able to filter on the policy but can't
Sent from my iPhone
09-12-2017 07:48 PM
I forwarded your request to enable filtering on authorization profiles to our internal teams. My guess is that any additional filters come with a cost of indexing.
09-13-2017 10:31 PM
CSCvf95756 opened on the request to allow filtering on Authorization Profiles.
As part of CSCvb46991, we found in ISE 2.1
that the column "Authorization Profile" displaying "Authorization Policy (rule name)" and
that the column "SelectedAuthorizationProfiles" mapping to "Authorization Profiles".
The fix corrected the column/field names:
Authorization Policy --> Authentication Policy (rule name)
Authorization Profile --> Authorization Policy (rule name)
09-13-2017 10:36 PM
Thanks.
So the Context Visibility->Endpoints is functioning as design and we can’t add in authorization profile without building a custom view?
If they can allow is to filter in the reports though that will be very nice. Most times we are looking at data in live logs or the reports.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
09-13-2017 11:06 PM
That is correct or at least for now, regarding the built-in views have fix sets of fields.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide