cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3104
Views
0
Helpful
2
Replies

Cisco ISE Time-based authorization

jinyuanbao
Level 1
Level 1

Hi guys,

How can i enforce different authorization policy at different time, like in the snapshot what attribute can i choose to accomplish the task below:

When the user logged in before 8am, he/she received the Policy A. When the same user logged in after 9am, he/she received  Policy B.

1 Accepted Solution

Accepted Solutions

georgehewittuk1
Level 1
Level 1

I can think of two ways this could be approached:

(1) Through the ISE authorisation policy and add a condition to hitting a policy -   Policy > Policy Elements > Conditions > Time and Date > Add. 

 

ise-com.PNG

(2) Time-Based DACLs.

 

Would recommend ensuring resilient NTP is setup on ISE and Network devices using same source.

 

 

View solution in original post

2 Replies 2

georgehewittuk1
Level 1
Level 1

I can think of two ways this could be approached:

(1) Through the ISE authorisation policy and add a condition to hitting a policy -   Policy > Policy Elements > Conditions > Time and Date > Add. 

 

ise-com.PNG

(2) Time-Based DACLs.

 

Would recommend ensuring resilient NTP is setup on ISE and Network devices using same source.

 

 

Thanks a lot

I was wondering what time is the Conditions > Time and Date based on, the UTC time of the ISE server or the switch/AP time?

I'm testing this function and find it seem it's based on the UTC time, not the current time zone time, and it's confusing to me.

Do you have any information about this, thanks..