<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and Infoblox Integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3890091#M471677</link>
    <description>&lt;P&gt;Thanks John!&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2019 07:31:47 GMT</pubDate>
    <dc:creator>Krzysztof Grabowski</dc:creator>
    <dc:date>2019-07-15T07:31:47Z</dc:date>
    <item>
      <title>ISE and Infoblox Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3886239#M471675</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please help me clarify a few points with ISE 2.4 to pxGrid integration with Infoblox 8.3? In one of our deployments with initial configuration we see&amp;nbsp;2 subscribers attached to the Grid:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;infoblox_client_subscribe_... with Core and SessionDirectory capabilities&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;infoblox_client_publish_.... with Core capability only&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;1. Which one of above is expected to issue the EPS quarantine events and should be placed in "EPS" client group (non of the two has "EndpointProtectionSevice" listed in the capabilities)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. The note in the ISE 2.2 integration guide states that " Cisco ISE 2.2 does not support any IPAM and HCP information". Has this changed in ISE 2.4 - can ISE consume these attributes?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 498px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40363i5EDCAA89BB967172/image-dimensions/498x115?v=v2" width="498" height="115" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;3. Does (and if so, how) ISE 2.4 consume "Network Insight" sourced information?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Would ISE create endpoints based on Infoblox provided data (seems not feasible as I don't see MAC in attributes)?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Would ISE enrich existing endpoints attributes?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;If above is true, can we use Infoblox sourced attributes in ISE profiling policies?&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 639px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40362iE7B150B80A98890C/image-dimensions/639x372?v=v2" width="639" height="372" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. Infoblox adds a few action groups: IPAM_Publish, DHCP_Publish etc... (don't have the exact names handy now). How should be assign these action groups to pxGrid subscribers in order to allow EPS and Infoblox attributes consumption on ISE?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 11:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3886239#M471675</guid>
      <dc:creator>Krzysztof Grabowski</dc:creator>
      <dc:date>2019-07-08T11:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Infoblox Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3889756#M471676</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Email me directly and we can schedule a webex to discuss.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the meanwhile, Infoblox DOES NOT send any information for ISE to consume. &amp;nbsp;Infoblox uses pxGrid 1.0 and DOES NOT use pxGrid 2.0.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Infoblox publishes the IPAM and DHCP tables, however, ISE DOES NOT CONSUME this information, this would be for ecosystem partners connected to the grid to subscribe to these topics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Infoblox consumes session information from ISE via pxGrid to the to populate the Infoblox IPAM table information. This is achieved by Infoblox subscribing to the pxGrid sessiondirectory topic. &amp;nbsp;Infoblox can also take mitigation actions on the endpoint by subscribing to the pxGrid EndpointProtection Service capability topic and is dependent on the Session:EPSStatus:Quarantine ISE authorization policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;
&lt;P&gt;jeppich@cisco.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2019 22:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3889756#M471676</guid>
      <dc:creator>jeppich</dc:creator>
      <dc:date>2019-07-13T22:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Infoblox Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3890091#M471677</link>
      <description>&lt;P&gt;Thanks John!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 07:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/3890091#M471677</guid>
      <dc:creator>Krzysztof Grabowski</dc:creator>
      <dc:date>2019-07-15T07:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Infoblox Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/4118564#M561692</link>
      <description>&lt;P&gt;John and Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone has experience moving to 2.6p2 with Infoblox solution? We are considering moving a client from 2.4 to 2.6p2 which is a trusted rev we have many clients on. Any items we should watch out for as we move to more recent code with regard to PXGrid / Infoblox? We will, of course, be updating the lab first, but know Infoblox has some set requirements, and can't find any compatibility details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just saw 2.7p1 is now blessed as well and sounds like that has good metrics as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you for your time in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 16:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-infoblox-integration/m-p/4118564#M561692</guid>
      <dc:creator>RockstarWiFi</dc:creator>
      <dc:date>2020-07-14T16:34:14Z</dc:date>
    </item>
  </channel>
</rss>

