<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE supported feature in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427248#M496693</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your response. Correct me if i am wrong with some detailed steps below:&lt;/P&gt;&lt;P&gt;- using ISE to scan all the devices inside the HO and branches.&lt;/P&gt;&lt;P&gt;- Group all the scanned devices into separate groups&lt;/P&gt;&lt;P&gt;- create different locations: Branch A, Branch B....&lt;/P&gt;&lt;P&gt;- Bind device group to specific Branch Location.&lt;/P&gt;&lt;P&gt;- Create policy base on specific location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question: can ISE support to create admin user for Branch A so that this admin only can add the devices belong to Branch A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;.:|:.:|:. Hai Nguyen&lt;/P&gt;&lt;P&gt;Systems Engineer | Cisco Systems Vietnam&lt;/P&gt;&lt;P&gt;Desk: +84 24 3974 6248 | Mobile: +84 904 373 746 | hanguye3@cisco.com&amp;lt;mailto:hanguye3@cisco.com&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2018 08:10:37 GMT</pubDate>
    <dc:creator>hanguye3</dc:creator>
    <dc:date>2018-06-27T08:10:37Z</dc:date>
    <item>
      <title>Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427245#M496690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am supporting our End-user on the requested feature below:&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;- They deployed ISE at DC and DR, each site has 03 virtual instances (PAN + PSN + MnT).&lt;/LI&gt;&lt;LI&gt;- They have many branches.&lt;/LI&gt;&lt;LI&gt;- The question is: can ISE support each branch only to add/edit/delete the policies related to those device which belongs to this branch or add new devices? &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, Branch A only can do AAA/COA policies with the devices or add new devices which belongs to Branch A and can not do with the devices belongs to Branch B.&lt;/P&gt;&lt;P&gt;It is something like separate multi-domains on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If support, kindly help to share us the detailed configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, pls help to propose any workaround solutions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Highly appreciate for any quick support. Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;hainm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 07:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427245#M496690</guid>
      <dc:creator>hanguye3</dc:creator>
      <dc:date>2018-06-27T07:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427246#M496691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it support it , you must add devices to ISE just in different location .&lt;/P&gt;&lt;P&gt;Devices in Branch A locate in Device group BRANCH A&lt;/P&gt;&lt;P&gt;Device in Branch B locate in branch B&lt;/P&gt;&lt;P&gt;Base on this locations you can create policy for them&lt;/P&gt;&lt;P&gt;like&lt;/P&gt;&lt;P&gt;Device type eq switch and device location in branch A&lt;/P&gt;&lt;P&gt;Than create authorization policy for them&lt;/P&gt;&lt;P&gt;This will instruct all devices try to connect switch from branch A will receive authorization policy for this location.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 07:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427246#M496691</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-27T07:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427247#M496692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your response. Correct me if i am wrong with some detailed steps below:&lt;/P&gt;&lt;P&gt;- using ISE to scan all the devices inside the HO and branches.&lt;/P&gt;&lt;P&gt;- Group all the scanned devices into separate groups&lt;/P&gt;&lt;P&gt;- create different locations: Branch A, Branch B....&lt;/P&gt;&lt;P&gt;- Bind device group to specific Branch Location.&lt;/P&gt;&lt;P&gt;- Create policy base on specific location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question: can ISE support to create admin user for Branch A so that this admin only can add the devices belong to Branch A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;hainm&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 08:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427247#M496692</guid>
      <dc:creator>hanguye3</dc:creator>
      <dc:date>2018-06-27T08:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427248#M496693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your response. Correct me if i am wrong with some detailed steps below:&lt;/P&gt;&lt;P&gt;- using ISE to scan all the devices inside the HO and branches.&lt;/P&gt;&lt;P&gt;- Group all the scanned devices into separate groups&lt;/P&gt;&lt;P&gt;- create different locations: Branch A, Branch B....&lt;/P&gt;&lt;P&gt;- Bind device group to specific Branch Location.&lt;/P&gt;&lt;P&gt;- Create policy base on specific location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question: can ISE support to create admin user for Branch A so that this admin only can add the devices belong to Branch A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;.:|:.:|:. Hai Nguyen&lt;/P&gt;&lt;P&gt;Systems Engineer | Cisco Systems Vietnam&lt;/P&gt;&lt;P&gt;Desk: +84 24 3974 6248 | Mobile: +84 904 373 746 | hanguye3@cisco.com&amp;lt;mailto:hanguye3@cisco.com&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 08:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427248#M496693</guid>
      <dc:creator>hanguye3</dc:creator>
      <dc:date>2018-06-27T08:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427249#M496694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again&lt;/P&gt;&lt;P&gt;I speak about network device not the endpoints&lt;/P&gt;&lt;P&gt;Add network devices in different location respective office&lt;/P&gt;&lt;P&gt;All endpoint associated to this network device you ca create policy based on location and device type like :&lt;/P&gt;&lt;P&gt;switch ,router,WLC and etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it is possible but i am not test this .And what kind of user for device administration like tacacs or something else&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 08:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427249#M496694</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-27T08:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427250#M496695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bro, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so can&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; background-color: #f6f6f6;"&gt; ISE support to create admin user for Branch A so that this admin only can add the devices belong to Branch A?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; background-color: #f6f6f6;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; background-color: #f6f6f6;"&gt;Br,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; background-color: #f6f6f6;"&gt;hainm&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 08:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427250#M496695</guid>
      <dc:creator>hanguye3</dc:creator>
      <dc:date>2018-06-27T08:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE supported feature</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427251#M496696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is some support.&lt;/P&gt;&lt;P&gt;Please check out the workaround for CSCvb55884. TAC has an internal doc detailing how it is done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 23:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-supported-feature/m-p/3427251#M496696</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-29T23:11:06Z</dc:date>
    </item>
  </channel>
</rss>

