<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE policy-sync between two ISE depyoments via REST-ApI in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474248#M505001</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roland,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an interesting one.&amp;nbsp; I am trying to think of the scenarios here where you could do this in a single deployment.&amp;nbsp; I think in most cases the only things the customer's network should need to access is the PSNs assuming the management company is doing all the ISE management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming the customers are separated by a VRF.&amp;nbsp; If you had a management VRF that was allowed to leak through to the customer VRFs you could put your Admin and M&amp;amp;T nodes there and then the PSNs would sit in the customer VRFs.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So Customer A PSNs sit in Customer A VRF, Customer B PSNs sit in Customer B VRF.&amp;nbsp; All PSNs are talking to the M&amp;amp;T and Admin nodes sitting in the management VRF via leaked routes.&amp;nbsp; As long as the subnets the PSNs and Admin/M&amp;amp;T aren't overlapping it could work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again just trying to think if is possible to do this in a single deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure Craig will tell me "No way!", but an interesting setup to think about.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 May 2018 13:20:48 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-05-15T13:20:48Z</dc:date>
    <item>
      <title>ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474243#M504996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there a way to sync authentication/authorization policies between two distinct deployments automatically via REST-API?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 16:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474243#M504996</guid>
      <dc:creator>rmueller@cisco.com</dc:creator>
      <dc:date>2018-05-14T16:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474244#M504997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see an issue why this can't be done, of course with a robust custom application/script.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please explain the use case - Why is it being sought? Will both deployments be changed or only one will be the (sync) source &amp;amp; the other (sync) destination? Will the two deployments be across a WAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 20:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474244#M504997</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-05-14T20:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474245#M504998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;The short answer is "partial support".&amp;nbsp; The current ERS API does support the export/import of many different objects but there are a number of items such as Auth Policy which cannot be imported (Admin UI export only).&amp;nbsp; Profiler objects can be exported and imported from Admin UI, but not API.&amp;nbsp; To see the range of object/policy items that can be synced via API, check the online SDK at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;primary-pan&amp;gt;:9060/ers/sdk&amp;nbsp; (Assumes ERS enabled under global deployment settings and ERS admin user created for admin access to ERS API.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 20:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474245#M504998</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-14T20:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474246#M504999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Krish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for the response. The use-case for having separate deployments is because this customer has multiple tenants with overlapping address spaces, which would mean we have duplicate NAD addresses. So the customer might have to use at least two separate deployments, but with same policies. So the policies (Authz-policies especially) would be managed on deployment1, and then they would like to replicate the policy to deployment2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland Mueller&lt;/P&gt;&lt;P&gt;CONSULTING SYSTEMS ENGINEER.SECURITY SALES&lt;/P&gt;&lt;P&gt;rmueller@cisco.com&amp;lt;mailto:rmueller@cisco.com&amp;gt;&lt;/P&gt;&lt;P&gt;Tel: +49 711 2391 1306&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;City Plaza - 4th Floor Rotebuehlplatz 21-25&lt;/P&gt;&lt;P&gt;STUTTGART&lt;/P&gt;&lt;P&gt;70178&lt;/P&gt;&lt;P&gt;Germany&lt;/P&gt;&lt;P&gt;cisco.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think before you print.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This email may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply email and delete all copies of this message.&lt;/P&gt;&lt;P&gt;Please click here&amp;lt;http://www.cisco.com/web/about/doing_business/legal/cri/index.html&amp;gt; for Company Registration Information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 11:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474246#M504999</guid>
      <dc:creator>rmueller@cisco.com</dc:creator>
      <dc:date>2018-05-15T11:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474247#M505000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please get your requests to the ISE product management team for feature request&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 12:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474247#M505000</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-15T12:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy-sync between two ISE depyoments via REST-ApI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474248#M505001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roland,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an interesting one.&amp;nbsp; I am trying to think of the scenarios here where you could do this in a single deployment.&amp;nbsp; I think in most cases the only things the customer's network should need to access is the PSNs assuming the management company is doing all the ISE management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming the customers are separated by a VRF.&amp;nbsp; If you had a management VRF that was allowed to leak through to the customer VRFs you could put your Admin and M&amp;amp;T nodes there and then the PSNs would sit in the customer VRFs.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So Customer A PSNs sit in Customer A VRF, Customer B PSNs sit in Customer B VRF.&amp;nbsp; All PSNs are talking to the M&amp;amp;T and Admin nodes sitting in the management VRF via leaked routes.&amp;nbsp; As long as the subnets the PSNs and Admin/M&amp;amp;T aren't overlapping it could work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again just trying to think if is possible to do this in a single deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure Craig will tell me "No way!", but an interesting setup to think about.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 13:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-sync-between-two-ise-depyoments-via-rest-api/m-p/3474248#M505001</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-05-15T13:20:48Z</dc:date>
    </item>
  </channel>
</rss>

