04-10-2019 10:42 PM
Hi Team,
One of my customers wants to create Policy Set with condition of user AD group (at cover of policy set), however, i don't see option to select the AD group name.
Is there any idea if we will support in upcoming releases.
Thanks,
Jay
Solved! Go to Solution.
04-10-2019 10:55 PM
While I understand the requirement, I doubt ISE would do this, since it is non sensical because authentication has not yet taken place. In the Policy Set Conditions were are checking the radius attributes for hints about the type of authentication (e.g. Service-Type, etc) and who is making the request (e.g. NDG which is basically checking the source IP of the request ). Even if ISE had the ability to check AD Group, you would first need to have passed authentication in order to care about the users AD attributes and groups. It would be very CPU intensive to perform this check for every radius request prior to the authentication stage.
AD Group checks are generally done during Authorization because it makes sense to do it here. Why does this not meet the customer’s needs?
04-10-2019 10:55 PM
While I understand the requirement, I doubt ISE would do this, since it is non sensical because authentication has not yet taken place. In the Policy Set Conditions were are checking the radius attributes for hints about the type of authentication (e.g. Service-Type, etc) and who is making the request (e.g. NDG which is basically checking the source IP of the request ). Even if ISE had the ability to check AD Group, you would first need to have passed authentication in order to care about the users AD attributes and groups. It would be very CPU intensive to perform this check for every radius request prior to the authentication stage.
AD Group checks are generally done during Authorization because it makes sense to do it here. Why does this not meet the customer’s needs?
04-10-2019 11:53 PM
04-11-2019 03:22 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide