02-22-2015 11:01 AM - edited 03-10-2019 10:28 PM
We want to create a policy set that hits on a endpoint identity group. An endpoint identity group contains a bunge mac-address which we can't filter out with radius user-name match which work fine for a vendor hit.
Does anybody got an idea of this is possible?
Solved! Go to Solution.
02-23-2015 07:18 PM
You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group.
I hope this helps!
Thank you for rating helpful posts!
02-23-2015 07:18 PM
You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group.
I hope this helps!
Thank you for rating helpful posts!
02-24-2015 12:15 AM
Thanks for clearing that up. Would be nice if you want to use MAB policy matching conditions would be expanded
02-24-2015 05:10 AM
No problem! You can always submit an enhancement request with your local Cisco team :)
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: