Dynamic attributes rule conditions
Dynamic attributes rule conditions allow you to specify access control rules based on real-time properties such as network objects, device types, locations, and security tags. These conditions determine how access control rules match traffic based on various attributes, optimizing policy flexibility and accuracy.
Types of dynamic attributes
Dynamic attributes include:
-
(source or destination) Dynamic objects (such as from the dynamic attributes connector)
The dynamic attributes connector enables you to collect data (such as networks and IP addresses) from cloud providers and send it to the so they can be used in access control rules.
For more information about the dynamic attributes connector, see About the dynamic attributes connector.
-
(source only) SGT objects contain tags either manually defined or defined in ISE. For more information, see Source and Destination Security Group Tag (SGT) Matching and Security Group Tag.
-
(source only) Location IP objects, defined by Cisco ISE
-
(source only) Device type objects, defined by Cisco ISE (also referred to as endpoint profile objects)
Combining objects in rules
Dynamic attributes can be used as source criteria and destination criteria in access control rules. Use these guidelines:
-
Objects of different types are ANDd together
-
Objects of a similar type are ORd together
For example, if you choose source destination criteria SGT 1, SGT 2, and device type 1, the rule matches if device type 1 is detected on either SGT 1 or SGT 2.
If you select both a security group tag, and a dynamic object that lists IP addresses, the rule matches if traffic with the tag originating from, or destined to, one of those IP addresses.