cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
269
Views
0
Helpful
2
Replies

ISE: Authorize on both ComminName and AlternativeName

Hi,

 

Today we are using ISE with authorization policys based on what the value in CommonName is in the device certificate.

So if CN contains "computer" ISE will put that device in VLAN X.

 

Now we are going to use Microsoft Intune as MDM. But Intune is limited and there isn't an option to specify what the CN should contain. We can, to some extend, decide is what should be in the Subject Alternative Name.

 

Can I in ISE have some policys based on CN and others based on SAN?

 

Regards,

Philip

 

2 Replies 2

jan.nielsen
Level 7
Level 7

Sure, you can use whaever attributes from the cert that ise supports in your authz policies. However like any other rule in your policy, you need to make sure the order of the rules fits your environment, and/or the conditions you are testing don't overlap. ISE stops looking through the policy on first match.

nspasov
Cisco Employee
Cisco Employee

Hi Philip, yes ISE can do this. You will have to create different "Certificate Authentication Profiles." One can be set to use: "Subject - Common Name" while the other one on "Subject - SAN DNS/e-mail/other"

Then you will use the different Certificate Authentication Profiles for different rules/Policy Sets in your Policy rules. 

I hope this helps!

 

Thank you for rating helpful posts!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: