cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1876
Views
5
Helpful
4
Replies
Jozef Cmorej
Beginner

Dymanic Filter-ID in ISE

Hello community,

I would like to ask you if it's possible to use a dynamic Filter-ID attribute in ISE. Our customer is applying different access control for VPN users using a custom attribute called Filter-ID on ACS 5.8. Using this attribute it is possible to use only one authorization profile and assign specific per user ACL configured on the firewalls.

aaa.jpg

Does ISE support this functionality?

 

As far as i know, it is possible to configure ISE to deploy per User dACL present in either the internal identity store or an external identity store. 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure-per-user-dynamic-access-contro.html

 

What if firewalls do not support dACL functionality? Which option could we use to follow the same functionality on ISE without need of creating a bunch of new authorization profiles?

 

Thank you.

1 ACCEPTED SOLUTION

Accepted Solutions

Correct, the built in common task "filter-id" option in ISE, can't be used with anything other than static text. But you should be able to use for example an internal user attribute or AD user attribute as the source for the content, if you add the av-pair manually. Just add filter-id attribute under the advanced attribute settings of the authz profile, in the example i added a custom attribute to internal users, but any string type attribute should do. Jan

View solution in original post

4 REPLIES 4
Mohammed al Baqari
VIP Advisor

Its a pre-defined attribute in ISE and can be assigned using authorization
profiles.

Thanks for you reply.
As far as I know you can assign this attribute as a result of the authorization profile only as a static value, not dynamically using a local or AD user's custom attribute, right?

Correct, the built in common task "filter-id" option in ISE, can't be used with anything other than static text. But you should be able to use for example an internal user attribute or AD user attribute as the source for the content, if you add the av-pair manually. Just add filter-id attribute under the advanced attribute settings of the authz profile, in the example i added a custom attribute to internal users, but any string type attribute should do. Jan

View solution in original post

Thanks Jan, that's exactly what I was looking for.
Content for Community-Ad