<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual Authz assignment to new endpoint in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3874318#M472317</link>
    <description>&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;I am familiar with creating policies to match these objects, I was hoping there was a "manual override" in a sense where I could choose the device from the endpoints list and manually assign the authz policy temporarily.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2019 14:13:17 GMT</pubDate>
    <dc:creator>scsc_tech</dc:creator>
    <dc:date>2019-06-17T14:13:17Z</dc:date>
    <item>
      <title>Manual Authz assignment to new endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3873254#M472241</link>
      <description>&lt;P&gt;Since ISE gains the most sensor data about an endpoint after it has received its DHCP lease, I need this to occur before I can create a well designed profile for the new device.&lt;/P&gt;&lt;P&gt;What I don't want to do is open up DHCP to any device that plugs into the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am hoping to do is plug in a new device, choose it from the endpoints list and manually assign an authz policy that will give it DHCP. Once ISE fully profiles the device, then I can use those attributes to build a well designed policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a function in ISE to manually assign an authz policy to an endpoint?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 17:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3873254#M472241</guid>
      <dc:creator>scsc_tech</dc:creator>
      <dc:date>2019-06-14T17:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Manual Authz assignment to new endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3873316#M472244</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You can create an identity group called pre-profile and create a policy to&lt;BR /&gt;match this group and assign author profile. Then you can assign your&lt;BR /&gt;endpoints manually to the group (static assigment). This will give them the&lt;BR /&gt;initial policy which can all them to get dhcp. Then if the profile is&lt;BR /&gt;changed and matched another policy, new author policy will be applied.&lt;BR /&gt;&lt;BR /&gt;Note that the pre-profile policy should be at the bottom of your policy set&lt;BR /&gt;to be last match&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jun 2019 18:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3873316#M472244</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-06-14T18:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Manual Authz assignment to new endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3874011#M472246</link>
      <description>&lt;P&gt;There are a number of ways you can achieve this but just to name a few:&lt;/P&gt;
&lt;P&gt;- Prer-defined Identity Group with the list of mac addresses&lt;/P&gt;
&lt;P&gt;- Match based on mac OUI&lt;/P&gt;
&lt;P&gt;- Match based on NDGs , NAS IP adress , NAS port type and the list goes on...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 07:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3874011#M472246</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-06-17T07:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Manual Authz assignment to new endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3874318#M472317</link>
      <description>&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;I am familiar with creating policies to match these objects, I was hoping there was a "manual override" in a sense where I could choose the device from the endpoints list and manually assign the authz policy temporarily.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 14:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3874318#M472317</guid>
      <dc:creator>scsc_tech</dc:creator>
      <dc:date>2019-06-17T14:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Manual Authz assignment to new endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3882975#M472318</link>
      <description>&lt;P&gt;I believe you already got the idea. ISE does not work that way. The closest is in&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493" target="_blank"&gt;Mohammed al Baqari&lt;/A&gt;'s response.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 04:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manual-authz-assignment-to-new-endpoint/m-p/3882975#M472318</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-02T04:15:44Z</dc:date>
    </item>
  </channel>
</rss>

