<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint registration via GUI/portal or whatever in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893490#M471432</link>
    <description>&lt;P&gt;Ok, I'll find another way to restrict the access to it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help !&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2019 11:08:23 GMT</pubDate>
    <dc:creator>Olivier Jessel</dc:creator>
    <dc:date>2019-07-19T11:08:23Z</dc:date>
    <item>
      <title>Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893429#M471328</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I recently deployed ISE 2.6 in a dispersed mode, and until now everything runs smoothly.&lt;/P&gt;&lt;P&gt;I have a requirement from business about giving access to the LAN to some "unmanaged and exotic" devices like scanners/3d printers, and so on...&lt;/P&gt;&lt;P&gt;Most of these just don't support dot1x or CWA, and they are also on the network only for a few days/weeks, during staging phase.&lt;/P&gt;&lt;P&gt;I am looking for a friendly way for the enduser to register these devices with their MAC addresses on the ISE, into the correct endpoints' group. Else, the security team can be surrounded from requests every day...&lt;/P&gt;&lt;P&gt;Any idea how to achieve that ? or maybe a different approach?&lt;/P&gt;&lt;P&gt;Thanks for your help &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 08:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893429#M471328</guid>
      <dc:creator>Olivier Jessel</dc:creator>
      <dc:date>2019-07-19T08:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893446#M471429</link>
      <description>You can use My Devices Portal on the ISE (Administration &amp;gt; Device Portal Management &amp;gt; My Devices). Create one portal for every group in portal settings and give a user friendly FQDN like printers, scanners etc. and share these FQDNs with the users. Users will login to the respective portals and register their devices accordingly which in the backend will be placed in the group you configure in the portal settings. You can configure policies to dictate the level of access to that endpoint group afterwards&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Jul 2019 09:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893446#M471429</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-19T09:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893459#M471430</link>
      <description>&lt;P&gt;Thanks Surendra,&lt;/P&gt;&lt;P&gt;Last question: can I also restrict the access to these portals to only some users or group of users (like based on AD group or local ISE users) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 09:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893459#M471430</guid>
      <dc:creator>Olivier Jessel</dc:creator>
      <dc:date>2019-07-19T09:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893484#M471431</link>
      <description>AFAIK, there isn’t such option yet.&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Jul 2019 10:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893484#M471431</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-19T10:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893490#M471432</link>
      <description>&lt;P&gt;Ok, I'll find another way to restrict the access to it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help !&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 11:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893490#M471432</guid>
      <dc:creator>Olivier Jessel</dc:creator>
      <dc:date>2019-07-19T11:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893661#M471433</link>
      <description>&lt;P&gt;You can use the API to write your own portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;what about using the PAN and giving access to certain groups? Its not nice like the my devices but they could also have RBAC to groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another option using my devices (hasn't been validated for a while)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-1-3-2-1-sponsor-authorization-on-secondary-attributes/ta-p/3641379" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-1-3-2-1-sponsor-authorization-on-secondary-attributes/ta-p/3641379&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 15:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893661#M471433</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-07-19T15:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint registration via GUI/portal or whatever</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893684#M471434</link>
      <description>&lt;P&gt;Yes. That is also an option provided the customer is ok with giving access to ISE on port 443 from the VLAN the users will be residing. Also, any user part of a specific user group can edit any device part of the specific endpoint group to which the access is given. For example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/41264iA6F8C6E56CD411E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the AD Group the user is a part of above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data access as follows :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image002.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/41265i3F177F380ABD5454/image-size/large?v=v2&amp;amp;px=999" role="button" title="image002.png" alt="image002.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Menu Access as follows :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image003.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/41266i9887A8802A0FBFF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image003.png" alt="image003.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Policy as follows :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image004.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/41267iCCFF59978B01B014/image-size/large?v=v2&amp;amp;px=999" role="button" title="image004.png" alt="image004.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The result will be as follows as when a user part of the AD group listed under Admin Group :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image005.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/41268iF5A4CE832B88FC01/image-size/large?v=v2&amp;amp;px=999" role="button" title="image005.png" alt="image005.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 16:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-registration-via-gui-portal-or-whatever/m-p/3893684#M471434</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-19T16:39:48Z</dc:date>
    </item>
  </channel>
</rss>

