<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: API Queries in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763791#M487180</link>
    <description>Please provide more details exactly the flow and why they need this. Might be another way to do this. Also what happens after they expire. What type of users are they? Will they be back? Is there any authentication taking place? What happens when the come back next day, etc &lt;BR /&gt;&lt;BR /&gt;The only way to do what you’re saying with the info you provided is to create your own tracking mechanism on Linux machine that calls api to put into one group and then another group when they want to change access&lt;BR /&gt;&lt;BR /&gt;Checking &lt;A href="http://cs.co/ise-guest" target="_blank"&gt;http://cs.co/ise-guest&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;What about guest access 1 hour in a day hotspot?&lt;BR /&gt;</description>
    <pubDate>Fri, 14 Dec 2018 14:38:16 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-12-14T14:38:16Z</dc:date>
    <item>
      <title>API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763169#M487122</link>
      <description>&lt;OL&gt;
&lt;LI&gt;What API can be used to whitelist MAC address with a time limit. By calling EndPoint API we can Add an end point, but it seems end point API does not have any start time and expiry time field ?&lt;/LI&gt;
&lt;LI&gt;Can a MAC address be added within time bound for &amp;nbsp;whitelisting does the MAC from whitelisted endpoint gets purged or removed &amp;nbsp;upon reaching time expiration ?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;3. Which API to be called for bulk uploading MAC address for exception list using template?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate any feedback on questions below&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 17:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763169#M487122</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2018-12-13T17:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763235#M487124</link>
      <description>There is no API with a time limit. You would have to build a system to monitor that and call the API when you wanted it removed.&lt;BR /&gt;&lt;BR /&gt;Which API to be called for bulk uploading MAC address for exception list using template?&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-1183657558" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-1183657558&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/#!bulk-operations/monitoring-bulk-execution-status" target="_blank"&gt;https://developer.cisco.com/docs/identity-services-engine/#!bulk-operations/monitoring-bulk-execution-status&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Dec 2018 19:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763235#M487124</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-13T19:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763375#M487176</link>
      <description>&amp;gt;&amp;gt; There is no API with a time limit. You would have to build a system to monitor that and call the API when you wanted it removed.&lt;BR /&gt;So time and date is available as a policy condition on ISE UI but those attributes not exposed to API’s ? is there a API I can use to track when this session ends and maybe use that session-ID to invoke API to kill/remove that endpoint ? Just trying to figure out how to automate this simple task of&lt;BR /&gt;mac whitelisted---&amp;gt;user connects----&amp;gt;time expires---&amp;gt;endpoint removed/purged&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Dec 2018 00:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763375#M487176</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2018-12-14T00:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763385#M487177</link>
      <description>Authorization rules are not tied to endpoint groups for removal. They simply authorize based on criteria. Endpoint purging removes endpoints with respect to days&lt;BR /&gt;&lt;BR /&gt;There are no variables assigned to an endpoint to remove from a list. No such mechanism. &lt;BR /&gt;&lt;BR /&gt;What exactly are you trying to accomplish? Please explain your use case . There might be a better way to accomplish this&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Dec 2018 01:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763385#M487177</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-14T01:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763394#M487178</link>
      <description>Whitelisting MAC for certain time period only. These whitelisted MACs only need access for certain time. Once the time expires, ISE should remove/delete/undo this MACs from whitelist.&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Dec 2018 02:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763394#M487178</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2018-12-14T02:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763773#M487179</link>
      <description>&lt;P&gt;As Jason said I think the easiest approach would be to put the MAC address into an endpoint identity group that is purged on a set schedule.&amp;nbsp; I use this for my ISE Temp Bypass concept.&amp;nbsp; The help desk, desktop team, etc can add MAC addresses into a ISE so they can troubleshoot a device, but the devices in the list are purged out every night at 3:00 a.m. when the purge job runs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 14:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763773#M487179</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-12-14T14:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: API Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763791#M487180</link>
      <description>Please provide more details exactly the flow and why they need this. Might be another way to do this. Also what happens after they expire. What type of users are they? Will they be back? Is there any authentication taking place? What happens when the come back next day, etc &lt;BR /&gt;&lt;BR /&gt;The only way to do what you’re saying with the info you provided is to create your own tracking mechanism on Linux machine that calls api to put into one group and then another group when they want to change access&lt;BR /&gt;&lt;BR /&gt;Checking &lt;A href="http://cs.co/ise-guest" target="_blank"&gt;http://cs.co/ise-guest&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;What about guest access 1 hour in a day hotspot?&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Dec 2018 14:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/api-queries/m-p/3763791#M487180</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-14T14:38:16Z</dc:date>
    </item>
  </channel>
</rss>

