<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sync ISE local user groups with external groups via LDAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760657#M487310</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;got the following request from one of my customers: They want to use ISE for device administration and want to do authentication as well as authorization based on group membership local on ISE. The users are also stored within AD, and of course they are also a member of a certain groups within AD. AD is attached to ISE via LDAP.&lt;/P&gt;
&lt;P&gt;Now they would like ISE to synchronize group membership between LDAP and ISE, which means, if a group membership in LDAP is changed, ISE should reflect this change in the local database as well.&lt;/P&gt;
&lt;P&gt;The reason why they want to do it this way is to be independent from Active Directory availability. If AD is not reachable, proper authentication/authorization still should happen.&lt;/P&gt;
&lt;P&gt;Is there someone out there already doing this? Of so, how?&lt;/P&gt;
&lt;P&gt;Any comment is welcome.&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2018 16:24:26 GMT</pubDate>
    <dc:creator>rmueller@cisco.com</dc:creator>
    <dc:date>2018-12-10T16:24:26Z</dc:date>
    <item>
      <title>Sync ISE local user groups with external groups via LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760657#M487310</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;got the following request from one of my customers: They want to use ISE for device administration and want to do authentication as well as authorization based on group membership local on ISE. The users are also stored within AD, and of course they are also a member of a certain groups within AD. AD is attached to ISE via LDAP.&lt;/P&gt;
&lt;P&gt;Now they would like ISE to synchronize group membership between LDAP and ISE, which means, if a group membership in LDAP is changed, ISE should reflect this change in the local database as well.&lt;/P&gt;
&lt;P&gt;The reason why they want to do it this way is to be independent from Active Directory availability. If AD is not reachable, proper authentication/authorization still should happen.&lt;/P&gt;
&lt;P&gt;Is there someone out there already doing this? Of so, how?&lt;/P&gt;
&lt;P&gt;Any comment is welcome.&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 16:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760657#M487310</guid>
      <dc:creator>rmueller@cisco.com</dc:creator>
      <dc:date>2018-12-10T16:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sync ISE local user groups with external groups via LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760704#M487311</link>
      <description>No, there is no option as such on the ISE to synchronize group membership.</description>
      <pubDate>Mon, 10 Dec 2018 17:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760704#M487311</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-10T17:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sync ISE local user groups with external groups via LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760748#M487313</link>
      <description>&lt;P&gt;I might be wrong here, but ACS had a feature that would allow to shadow the AD user credentials and create a local copy on ACS in case the AD connection was unavailable.&amp;nbsp; That doesn't exist in ISE either.&lt;/P&gt;
&lt;P&gt;I guess the onus is on the AD infrastructure to be 100% available &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 19:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sync-ise-local-user-groups-with-external-groups-via-ldap/m-p/3760748#M487313</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-12-10T19:14:37Z</dc:date>
    </item>
  </channel>
</rss>

