cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
561
Views
0
Helpful
3
Replies

ISE 1.3 Policy Set

mvdsteen1982
Level 1
Level 1

We want to create a policy set that hits on a endpoint identity group. An endpoint identity group contains a bunge mac-address which we can't filter out with radius user-name match which work fine for a vendor hit.

Does anybody got an idea of this is possible?

1 Accepted Solution

Accepted Solutions

nspasov
Cisco Employee
Cisco Employee

You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group. 

I hope this helps!

 

Thank you for rating helpful posts!

View solution in original post

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

You cannot create a "Policy Set" matching condition based on an endpoint identity group. You have to choose one of the available attributes. For instance, you can match against a NAD group or WLAN ID. Once inside the "Policy Set" you can create different authentication and authorization rules that can reference an endpoint group. 

I hope this helps!

 

Thank you for rating helpful posts!

Thanks for clearing that up. Would be nice if you want to use MAB policy matching conditions would be expanded
 

No problem! You can always submit an enhancement request with your local Cisco team :)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: