<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP-SGT Mapping Deployed from ISE - config saving in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916657#M457390</link>
    <description>&lt;P&gt;In my opinion when ISE is the pushing static IP-SGT mappings it acts like a kind of automation tool that the engineer is using in a controlled way as he needs to trigger the deployment manually using the deploy button so no unexpected saves can happen. It doesn't make a lot of sense to connect to each and every affected device separately and save the config manually when the automation is used, if not doing it automatically then at least letting the user decide if the save should be done.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2019 11:39:54 GMT</pubDate>
    <dc:creator>Michal Olsovsky</dc:creator>
    <dc:date>2019-08-30T11:39:54Z</dc:date>
    <item>
      <title>IP-SGT Mapping Deployed from ISE - config saving</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3915855#M457385</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using ISE to deploy IP-SGT mappings to several switches and we just observed that after the deployment the switch config is not saved automatically (by ISE). Obviously if the config is not saved manually and a power outage occurs then the new mappings are lost.&lt;/P&gt;&lt;P&gt;Any feedback will be welcomed, we are interested to see if this is as designed or maybe a bug so we will open a TAC case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 06:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3915855#M457385</guid>
      <dc:creator>Adrian Lazar</dc:creator>
      <dc:date>2019-08-29T06:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: IP-SGT Mapping Deployed from ISE - config saving</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916093#M457386</link>
      <description>&lt;P&gt;My guess is that it is by design.&amp;nbsp; IP-SGT mappings change over time and ISE regularly communicates with the switches using SXP to ensure the mappings are there, updated, or removed as necessary.&amp;nbsp; If the switch were to restart, it would re-establish the SXP connection with ISE and the mappings would be pushed down again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Someone could be in the middle of making other changes on the switch and I don't necessarily think it would be good for ISE to save the configuration which would include other changes outside of IP-SGT mappings.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 13:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916093#M457386</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-08-29T13:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: IP-SGT Mapping Deployed from ISE - config saving</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916629#M457387</link>
      <description>I think it is intentionally not done since saving the changes on the switch does not save just the changes made by ISE but by everyone. You don’t want to end up in a situation where a network device administrator is in the middle of testing something and ISE pushed down the mappings and saved the changes.&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Aug 2019 10:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916629#M457387</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-08-30T10:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: IP-SGT Mapping Deployed from ISE - config saving</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916657#M457390</link>
      <description>&lt;P&gt;In my opinion when ISE is the pushing static IP-SGT mappings it acts like a kind of automation tool that the engineer is using in a controlled way as he needs to trigger the deployment manually using the deploy button so no unexpected saves can happen. It doesn't make a lot of sense to connect to each and every affected device separately and save the config manually when the automation is used, if not doing it automatically then at least letting the user decide if the save should be done.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 11:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916657#M457390</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2019-08-30T11:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: IP-SGT Mapping Deployed from ISE - config saving</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916685#M457392</link>
      <description>Adding to the above comments. You can configure the CTS environment data downloads, etc. in ISE for individual NADs under the advanced trustsec configuration. CTS pacs are lost upon reboot as well, but stored in ISE. So once the NAD is up it will have a cts provisioning job where it reaches back out to ISE. Based on conversations with Cisco I believe it is road-mapped to eventually have NADs keep their PACs upon reboot.</description>
      <pubDate>Fri, 30 Aug 2019 12:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-sgt-mapping-deployed-from-ise-config-saving/m-p/3916685#M457392</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-08-30T12:27:37Z</dc:date>
    </item>
  </channel>
</rss>

