02-22-2015 11:01 AM - edited 03-10-2019 10:28 PM
We want to create a policy set that hits on a endpoint identity group. An endpoint identity group contains a bunge mac-address which we can't filter out with radius user-name match which work fine for a vendor hit.
Does anybody got an idea of this is possible?
Solved! Go to Solution.
02-23-2015 07:18 PM
You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group.
I hope this helps!
Thank you for rating helpful posts!
02-23-2015 07:18 PM
You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group.
I hope this helps!
Thank you for rating helpful posts!
02-24-2015 12:15 AM
Thanks for clearing that up. Would be nice if you want to use MAB policy matching conditions would be expanded
02-24-2015 05:10 AM
No problem! You can always submit an enhancement request with your local Cisco team :)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide