cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
838
Views
0
Helpful
4
Replies

ISE Compound Condition Problem

acontes
Level 1
Level 1

Hi, I know it is possible to configure, because I have it in the production environment, but in my lab I have a problem with a compound condition:

I try to configure an authorization compound condition. I have wireless users in the local identity store and in an external ldap store. To authorize both groups, I want to create a compound condition like:

LDAP01:ExternalGroups EQUAL CN=WLAN-Access1,O=WLAN or

LDAP01:ExternalGroups EQUAL CN=WLAN-Access2,O=WLAN

and so on. So far so good. I can select the LDAP groups. But when I try to add the local store I am not able to select the internal identity group. I add an attribute:

IdentityGroup:Name EQUAL ....

I cklick on the "down arrow" to select the correct internal group, but everything I am able to select is "IdentityGroup:Name" and not the real name of the group. So the result is:

IdentityGroup:Name EQUAL IdentityGroup:Name

This makes no sense to me. Also I am not able to search for the group.

Any hints on that?

4 Replies 4

jan.nielsen
Level 7
Level 7
Internal User Groups in ISE are configured with the box to the left if the condition list, so you won't be able to combine internal and ldap groups in one rule.

I dont get it. Maybe its unclear what I mean. Here is a screenshot.

802.1x-VIP is an internal user group with internal users. CN=WLAN-Access... are external LDAP groups.

My problem is, that in my Lab, I am not able to configure this internal group as a condition. I just cannot select an internal group. The question is: Why.

I think you'd need to create a separate policy rule with the same policy but instead of the compound condition, just select the identity group you want from the dropdown list (see green area in attached screenshot).

This way you've got one rule for your LDAP groups and one for you identity group.

Maybe thats a solution, yes. But there is still the main question: Why can't I add a local identity group to the compound condition?!

ISE 1.2.1 Patch 7