Saving Attributes for Re-Use
ISE offers the ability to save conditions to the library to make it much easier to reuse them in other policies. To show this, let’s go back into your example Authorization Policy and save a few of the conditions.
From the ISE GUI, perform the following steps:
- Navigate to Policy > Authorization.
- Edit the Employee and CorpMachine rule.
- Expand the conditions.
- Click Add All Conditions Below to Library, as shown in Figure 13-34.
Figure 13-34.Add All Conditions Below to Library
This is adding the full set of conditions, including the AND operator.
- Provide a name for this new saved condition, such as EmployeeFullEAPChain.
- Finish editing the rule.
- Click Save.
As shown in Figure 13-35, the Authorization Policy text is simplified now with the name of the saved conditions instead of the raw attributes.
Figure 13-35.Authorization Policy After Saving Conditions to Library
Next, save the Employees group for AD as a condition:
- Navigate to Policy > Authorization.
- Edit the Employee iDevices Rule.
- Expand the conditions.
- Click the cog on the right-hand side of the Employees line.
- Choose Add Condition to Library.
- Name the condition Employees.
- Click the green check mark.
Figure 13-36 displays the saving of Employees to the Conditions library.
Figure 13-36.Saving Employees to Library
- Click Done to finish editing the rule.
- Click Save.
Figure 13-37 shows the final Authorization Policy.
Figure 13-37.Final Authorization Policy