11-27-2024 12:36 AM - edited 11-27-2024 12:36 AM
Hello Cisco ISE experts,
I'm new to Cisco ISE V3.2 and I'm struggling with Policy Sets and the embedded "Default"- Authentication Policy.
To make the output of Radius Live Log more meaningful, I would like to replace the word "Default" in the according policy set with a more meaningful string like "MAC-Check Internal Endpoints".
But I cannot find the Editor Button for this within the Ruleset Editor page.
I have also tried to add a second Authentication Policy Rule with a more meaningful Rule Name in front of the "Default" Authentication Policy with same Use Parameters, but receive the following cryptic error-message in that case.
Internal Check of MAC-Address - could not be saved.
Rule Condition is not properly configured for rule: Internal Check of MAC-Address
Obviously I do not understand the concept behind this "Default" very well.
Who knows how I can substitute this sucking "Default" with a more meanful expression ?
Thank You in advance
Greetings from Frankonia
Wini
Prime V3.10.4 and ISE V.3.2 (formerly V2.4)
11-27-2024 06:31 PM
You cannot change the name of the Default rule. You would need to create a rule above it that matches your session criteria.
The whole point of the Default rule is that it is the one hit when none of your specific configured rules are hit.
11-29-2024 12:12 AM - edited 11-29-2024 12:13 AM
Hello Greg,
thank You for Your reply.
I already tried to create a rule above the default rule with meaningful title and same settings as the Default rule as You can see from my attached screenshot. Unfortunately I receive the following error-message:
Internal Check of MAC-Address - could not be saved.
Rule Condition is not properly configured for rule: Internal Check of MAC-Address
In the Cisco Press book for ISE I can see that initally there are three possible options here:
- MAB -Dot1x and -Default
Also the following Guide shows these three option in V2.4:
How can I change from Default to MAB instead in an already defined ruleset ?
Thank You for Yor help
Kind regards
Wini
11-29-2024 12:37 AM
can you share policy set
MHM
11-29-2024 01:09 AM
11-29-2024 12:48 PM
below how you can use ipsk,
we dont use MAB for ipsk we but we use mac in authz/authc policy
MHM
11-30-2024 12:43 PM
You cannot save the new rule without adding a condition. Try Wireless_MAB.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide