cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1651
Views
5
Helpful
11
Replies

ISE TACACS Device Fitlers

awatson20
Level 4
Level 4

I am migrating from ACS to ISE for TACACS.  In ACS, we used device filters to define a list of network devices, and used that to create rules to match or not match within access policies.  I am cannot figure out how to do the same function in ISE.  

2 Accepted Solutions

Accepted Solutions

Yo can do that by selecting "Network access: Device IP address"

Hope it answers your query.

Regards

Gagan

ps : rate as correct if it helps!!!!

View solution in original post

11 Replies 11

Gagandeep Singh
Cisco Employee
Cisco Employee

In ISE, in order to create device filter, the option has changed to compound condition.

Work Centers > device administration > policy elements > conditions > Authorization compound condition.

You can create a rule where you can 'n' number of device type in it by selecting Create New condition.

Regards

Gagan

ps : rate as correct if it helps!!!!

But how do you create/define a list of IP Addresses from a Compound condition based on IP Address?  For example, I want to define a list of IP Addresses and then apply that to a policy rule to match or to not match?

Yo can do that by selecting "Network access: Device IP address"

Hope it answers your query.

Regards

Gagan

ps : rate as correct if it helps!!!!

Thanks.

Let me know if that works for you or not.

Use this thread for any concerns.

Regards

Gagan

ps : rate as correct if it helps!!!!

Gagan, when creating the compound condition, where do you actually define the IP Address list?

The shared screenshot is correct. Just need to add IP address on the next blank option.

You can add multiple entries for the same.

Once you have the IP Addresses defined as a compound auth condition, how do you apply that as a filter for those specific IP Addresses?  Is that under the admin policy sets?  How would the rule need to be defined?

You need call the condition in Authz rule by selecting the condition.

Already shared information.

Regards

Gagan

This works, but is it possible to create compound condition using a network range instead of a single IP Address?  Such as 172.31.2.0/24, instead of having to list them individually.

No you have to create individual IPs' :).

Regards

Gagan

ps : rate if it helps!!!