cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2475
Views
0
Helpful
2
Replies

Cisco ISE Policy Set for a specific switchport

Hi,

 

I've rolled out dot1x via Cisco ISE onto a customer user network. The user access switches are 2960X. The version of ISE is 2.7 Patch 2.

 

There are a few issues, specifically with a group of users. I want to created a new policy set for one user in particular and put this policy above the policy for everyone else. I want the policy to do the same as the working policy except for it to only allow a specific network port e.g. Switch5, interface Gi3/0/30. For here, they will get a test dACL that I will use for testing purposes

 

I have configured the following and enabled it but the user is still authenticating against the all users policy.

 

Unclassified : Normalised Radius : Radius Flow Type equals Wired802.1x

Network Device : Network Access : NetworkDeviceName equals switch5

Port : Radius : NAS-Port-ID equals Gi3/0/30

 

I hope all this makes sense. I've attached a few screenshot for clarification.

 

Thanks

Anthony.

 

2 Accepted Solutions

Accepted Solutions

Since these two policies are doing the exact same thing (except for the dACL) could you remove the nas-port-id condition (and the dACL) to verify that you are matching on the device name.  If this match is successful, then we know that the issue is with the port id.

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

I removed the nas-port-id and found that it was the NAD device in ISE that was configured with a different name to the real switch name (embarrassing). Thanks for your help. 

View solution in original post

2 Replies 2

Since these two policies are doing the exact same thing (except for the dACL) could you remove the nas-port-id condition (and the dACL) to verify that you are matching on the device name.  If this match is successful, then we know that the issue is with the port id.

--
Please remember to select a correct answer and rate helpful posts

I removed the nas-port-id and found that it was the NAD device in ISE that was configured with a different name to the real switch name (embarrassing). Thanks for your help. 

Review Cisco Networking for a $25 gift card