cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2019
Views
0
Helpful
6
Replies

AuthZ policy Calling-Station-ID local group Cisco ISE

Rene Rolsted
Level 1
Level 1

Is it possible to make a AuthZ policy that points to a local ISE group with the mac addresses?

This works fine, but only 1 MAC address

(Radius:Called-Station-ID CONTAINS test-ssid AND Radius:Calling-Station-ID EQUALS 4C:7C:5F:C2:7B:7C )

I try this, but this will not work:

(Radius:Called-Station-ID CONTAINS test-ssid AND Radius:Calling-Station-ID CONTAINS IdentityGroup:Name:test-mac-group)

1 Accepted Solution

Accepted Solutions

Please use Radius:Called-station-id CONTAINS instead of EQUALS ise-test

~ Jatin

~Jatin

View solution in original post

6 Replies 6

Jatin Katyal
Cisco Employee
Cisco Employee

In AuthZ policy, please select you endpoint group by clicking on any and then select the radius called station id. Please refer the image.

~ Jatin

~Jatin

Thank you, Jatin - but it's not work.

I think missing some settings on the WLC

Please use Radius:Called-station-id CONTAINS instead of EQUALS ise-test

~ Jatin

~Jatin

If in case you still some issue then get the screen shot of ISE live authentication - detailed steps of the endpoint session.

~ Jatin

~Jatin

Thank you, Jatin - this work

Radius:Called-station-id CONTAINS instead of EQUALS ise-test

Best Regard
/René

Great :)

~Jatin