cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1618
Views
5
Helpful
4
Replies

ISE Authorization Compound Condition with Local User Groups

roadracers
Level 1
Level 1

I am trying to create an Authorization Policy that will use the User Groups I have defined on ISE. I am unable to find the correct attribute in the conditional expression that will look at the ISE User Group. I have been able to make this work with an External Identity Source (AD), just not the internal user group. If you look in the picture, it is the first line I am trying to modify to verify against the ISE User Group that I created. Anyone help with this?

4 Replies 4

jan.nielsen
Level 7
Level 7

Internal ISE group condition only works by selecting it in the user group selection to the right of the condtions in your authorization rule,you cant use it as a "condition".

Thank you, I finally figured it out. Just different that AD groups are in the conditional expression, but the internal user groups are not.

Hi,

can you please explain how you did it?

i tried but getting authentication fail error in my mobile.

regards,

Yes. So like Jan said above, you can't use it in the compound condition, but you can use it on the authorization policy page. Let me show you.

Where the arrow is on the main authorization page, replace "Any" with the local identity group or user. Then on the policy compound condition, add two conditions, if you are setting up Radius: network access:authentication method equals PAP_ASCII and Radius:NAS-Port-Type Vitual.