cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1032
Views
0
Helpful
1
Replies

Using IdentityGroup as policySet condition

ping2balaji
Level 1
Level 1

Hi ,

 

I am using ISE-eval  version 3.1.

I am new to cisco ise and trying to configure a set of authorization profiles for different category of users such as doctors/nurses. 

For this purpose:

1.i have created internal users(identities) and grouped them into User Identity Groups names as 'doctors'/'nurses'.

2. Now i have created new conditions under policyElements as:  a) IdentityGroup·Name = UserIdentityGroups:doctors and b) IdentityGroup·Name = UserIdentityGroups:nurses.

3. Then moved to create a new Policy Set to link an already created authorization-policy and authentication-policy. Under 'conditions' column, the condition studio pops-up , but i cannot see the conditions created in above step-2. Attached reference screenshot for the same

 

May i know if i have missed any steps?

Is it not possible to define a policyset based on identityGroup? If not possible then how to achieve the same in my case where i want to apply different authorization-policy(and acls etc) for different usergroups defined internally in the cisco-ise.

 

Also if 'IdentityGroup' based condition is not used in policy-set why its shown as option while creating conditions? is it used for some other purpose? please clarify.

 

 

 

Thanks,

...Balaji

1 Accepted Solution

Accepted Solutions

ping2balaji
Level 1
Level 1

Hi all, 

After debugging it looks like i tried to set condition in authN-Policy under policy-set, and hence the identityGroup name match condition was not showing up. 

When i tried to configured authZ-Policy condition i am able to see identityGroup name match condition there which was exactly what i was looking for.

This can be considered answered.

 

Thanks,

...Balaji.J

View solution in original post

1 Reply 1

ping2balaji
Level 1
Level 1

Hi all, 

After debugging it looks like i tried to set condition in authN-Policy under policy-set, and hence the identityGroup name match condition was not showing up. 

When i tried to configured authZ-Policy condition i am able to see identityGroup name match condition there which was exactly what i was looking for.

This can be considered answered.

 

Thanks,

...Balaji.J