cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

701
Views
0
Helpful
1
Replies
Flavio Costa
Cisco Employee

ISE - MAB Group Structure

Hi experts!

Regarding ISE:

1. Are there indications or suggestions on the maximum number of sub-levels for MAB group structure?

2. We would like to ask if the creation and manual static assignment of an endpoing object (MAB) to a static policy assignment could cause a decrease of advanced licenses, under the following conditions:

A. Static assignment (Policy Assignment + Identity Group) and Policy Assignment parameter in the authorization policies

B. Static assignment (Policy Assignment + Identity Group) but without using Policy Assignment parameter in the authorization policies

  We currently know that the static assignment (profiling) and the policy usage actually (officially) reduces the advanced licenses and we were wondering what could happen if the endpoint would be manually converted to static.

Regards,

Flavio

1 REPLY 1
Timothy Abbott
Cisco Employee

Hi Flavio,

If an endpoint was dynamically profiled in ISE and then that policy used in authorization policy, it would then use a license.  However, if the endpoint was statically assigned to and endpoint policy, it would not use a license.  The profile policy structure are built on individual profile polices.  What I mean by that is each policy category and sub-category are actual profile policies that can be use to classify endpoints.  I'm not aware of any limitations on the number of sub-categories you can create.

Regards,

Tim

Content for Community-Ad