Hello Zdenek,
thanks for your prompt answer. First I set the policy mapping as vlan tagged, only at access control, not at policy.....
![057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png 057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png](/t5/image/serverpage/image-id/5233iA478D42C7B8D8644/image-size/large?v=v2&px=999)
Second I create the profile...
![057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png 057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png](/t5/image/serverpage/image-id/3782iF8CF8AFDE2E9B9A9/image-size/large?v=v2&px=999)
And third I create the rule....
![057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png 057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png](/t5/image/serverpage/image-id/3913i0D1EDB8FB37C756F/image-size/large?v=v2&px=999)
At this moment I won´t use any
Policy Roles, I will use it later if it is necessary. I this the wrong way or should I use already Policy Roles at this point too?
Best Bernd