<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:ISE base license and import of enddevices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127983#M146048</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you check the ad group of a user, that is part of the authentication phase and consumes a base license.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Feb 2013 22:19:39 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-02-01T22:19:39Z</dc:date>
    <item>
      <title>ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127972#M146037</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Been going through the intire internet (or so it seems) and most guides and tips are about features that is included in the advanced license, profiling and so on.&lt;/P&gt;&lt;P&gt;I am facing a case where base license should be enough. But I am confused about the import of endpoints. &lt;/P&gt;&lt;P&gt;When using the base license is the only way to import devices manualy or through file or LDAP? Can't ISE scan the network an pick up MAC addresses automaticly?&lt;/P&gt;&lt;P&gt;We dont have LDAP and about 20 000 endpoints, so adding them manualy or to a csv-file is too much work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127972#M146037</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2019-03-11T02:58:56Z</dc:date>
    </item>
    <item>
      <title>ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127973#M146038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phillip,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, those are the only 2 methods to lookup mac addresses, those are the only two methods that ISE will only apply base licenses. If you choose to have ISE scan your network for devices then that would be seen as "dynamic profiling" which is an advanced feature. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 17:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127973#M146038</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-16T17:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127974#M146039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Tarik. You are a goldmine when it comes to information about ISE &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it is time to go MAC address hunting!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: A second question. If I have the eval license. What do I have to turn off in ISE beside the Profiling Configuration to evaluate only base license?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 06:28:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127974#M146039</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-01-17T06:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127975#M146040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And another question about base license (I can guess the answer but some confirmation would be good) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user has registered a device through the &lt;SPAN style="font-size: 10pt;"&gt;My Devices Portal webpage the device will end up in RegisteredDevices Identity Group. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is there anyway to change this? Is there&amp;nbsp; a way for the user to choose what group the device should be in? Or is the only way to change ID group that an administrator of ISE do it manually?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem that we are facing are that some devices should go to VLAN X and other on VLAN Y. But since they all are assigned to the RegisteredDevices group there is no way to &lt;SPAN style="font-size: 10pt;"&gt;differentiate them in a authorization profile. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: Just found out that this might be solved in 1.2. It will implement the use of Endpoint Profile as an attribute in authorization profiles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 14:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127975#M146040</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-01-17T14:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127976#M146041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can not do this but I have a trick that you can use. You can build another web portal (device registration web authenticaion), then you can set the endpoint identity group you want to stick the users that hit this portal in. Let me know if that leads you down the right path. i can elaborate if you want me to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 06:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127976#M146041</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-18T06:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127977#M146042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That sounds intresting. Do you mean builing an webportal out side of ISE and somehow connect it to ISE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like the most is a dropdown menu on the device registration page where the user can choose what device they are &lt;SPAN style="font-size: 10pt;"&gt;registrering.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 07:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127977#M146042</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-01-18T07:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127978#M146043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some overview on the device registration portal I was discussing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-26667"&gt;https://supportforums.cisco.com/docs/DOC-26667&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is set this portal above the policy that registers the endpoints manually, it is a bit tedious but give this a try and see if you like it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 15:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127978#M146043</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-18T15:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127979#M146044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read through it and it looks intresting. I don't have access to ISE at the moment so I can't do any testing. But you are writing about the guest portal. Can this be used on the My Device portal too? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 08:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127979#M146044</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-01-21T08:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127980#M146045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind that the article you read is a different type of portal. It is a portal that is designed to statically assign an endpoint to a endpoint group. So you can use this portal once a device is mapped to the RegisteredDevices endpoint group after a user registers their device. After you create the authorization profile that utilizes this portal, you can then use other condtions in order to move the registereddevice to another endpoint group. This solution doesnt scale well but I wanted to throw this out there as an option that may work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps.&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 08:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127980#M146045</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-21T08:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127981#M146046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aha thank you! Now I understand it a bit better. Will lab it when I get my hands on ISE again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 08:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127981#M146046</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-01-21T08:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127982#M146047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik and others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question on the same subject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you are running base license can you still check if the computer is in a Active Directory group? and then do authorization policy based on that. Or is it ONLY mac-address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Philip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 15:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127982#M146047</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-02-01T15:38:09Z</dc:date>
    </item>
    <item>
      <title>Re:ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127983#M146048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you check the ad group of a user, that is part of the authentication phase and consumes a base license.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 22:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127983#M146048</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-02-01T22:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127984#M146049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thanks. What I want to do is to check the ad group of a device not user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 09:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127984#M146049</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-02-04T09:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE base license and import of enddevices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127985#M146050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Philip,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can check computer in AD group i.e machine auth. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 21:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-base-license-and-import-of-enddevices/m-p/2127985#M146050</guid>
      <dc:creator>shekharmore003</dc:creator>
      <dc:date>2013-02-22T21:52:50Z</dc:date>
    </item>
  </channel>
</rss>

