<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Profiling - What is &amp;quot;exception action&amp;quot; and &amp;quot;static assignmen in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046165#M185194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exception action is an action you can trigger in a profiling policy (such as an nmap scan or CoA) the default exception action is to trigger CoA when a endpoint is profiled from unknown to known, and when an endpoint is deleted. An exception action for example will be to trigger CoA when a device is profiled as a Cisco Device, so they can match another condition after the dhcp information is received after the initial authentication, so know they probably match a Cisco phone 7975...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static assignment is to statically assign an endpoint to a identity group so they dont bounce around and get reprofiled. Once they meet this condition they are stuck until you delete the endpoint. Usually static entries are present when up load multiple endpoints via csv...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Sep 2012 20:07:26 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-09-06T20:07:26Z</dc:date>
    <item>
      <title>ISE Profiling - What is "exception action" and "static assignment"?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046164#M185191</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to ISE and catching up on things. I am at the profiler and could not clearly understand the two things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Exception Action. - what is this for and when/how to use it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- static assignment - again, not sure of the real purpose?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would appreciate if some can explain me these two things or point me to a good document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mohan&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046164#M185191</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2019-03-11T02:30:38Z</dc:date>
    </item>
    <item>
      <title>ISE Profiling - What is "exception action" and "static assignmen</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046165#M185194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exception action is an action you can trigger in a profiling policy (such as an nmap scan or CoA) the default exception action is to trigger CoA when a endpoint is profiled from unknown to known, and when an endpoint is deleted. An exception action for example will be to trigger CoA when a device is profiled as a Cisco Device, so they can match another condition after the dhcp information is received after the initial authentication, so know they probably match a Cisco phone 7975...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static assignment is to statically assign an endpoint to a identity group so they dont bounce around and get reprofiled. Once they meet this condition they are stuck until you delete the endpoint. Usually static entries are present when up load multiple endpoints via csv...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 20:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046165#M185194</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-06T20:07:26Z</dc:date>
    </item>
    <item>
      <title>ISE Profiling - What is "exception action" and "static assignmen</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046166#M185196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are the two types of authorization&amp;nbsp; policies that you can configure: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•Standard &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•Exception &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Standard policies are policies created to&amp;nbsp; remain in effect for long periods of time, to apply to a larger group of users&amp;nbsp; or devices or groups, and allow access to specific or all network&amp;nbsp; endpoints&lt;BR /&gt;contrast, exception policies are appropriately named because this&amp;nbsp; type of policy acts as an exception to the standard policies. Exception polices&amp;nbsp; are intended for authorizing limited access that is based on a variety of&amp;nbsp; factors (short-term policy duration, specific types of network devices, network&amp;nbsp; endpoints or groups, or the need to meet special conditions or permissions or an&amp;nbsp; immediate requirement).&lt;BR /&gt; &lt;BR /&gt;Exception policies are created to meet an&amp;nbsp; immediate or short-term need such as authorizing a limited number of users,&amp;nbsp; devices, or groups to access network resources. An exception policy lets you&amp;nbsp; create a specific set of customized values for an identity group, condition, or&amp;nbsp; permission that are tailored for one user or a subset of users. This allows you&amp;nbsp; to create different or customized policies to meet your corporate, group, or&amp;nbsp; network needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static Assignment :&lt;BR /&gt;You can assign an&amp;nbsp; endpoint to an identity group statically. In such cases, the Profiler service&amp;nbsp; does not change the identity group the next time during the policy evaluation&amp;nbsp; for these endpoints, which are previously assigned dynamically to endpoint&amp;nbsp; identity groups in Cisco ISE. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 10:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-what-is-quot-exception-action-quot-and-quot-static/m-p/2046166#M185196</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-05-28T10:53:01Z</dc:date>
    </item>
  </channel>
</rss>

