<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity PSK Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599631#M510519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;like something like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="BRKSEC-3699.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/116703_BRKSEC-3699.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Apr 2018 20:17:41 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-04-24T20:17:41Z</dc:date>
    <item>
      <title>Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599628#M510516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer that is looking to reduce the number of SSIDs and create some control around their PSK networks. The customer's network is an educational network (university) that hosts many networks across many different endpoints (around 80k). The client is looking at IPSK but were under the assumption that it would operate much like the Ruckus' iteration of DPSK, however that isnt the case. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We looked at many options and it seems as if the av-attribute doesnt allow you to reference a dynamic condition such as an AD attribute. The goal of the solution that i have in mind is to create a policy that references the AD attribute and have users register their device through the device registration portal, but echo back the client's AD attribute that is unique to them as their PSK. Zero touch is preferred but device registration is acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a feature request or a solution that someone could walk me through, the goal of this exercise is to reduce the risk of the PSK and also reduce the number of ISE authorization profiles/policies to create in order to support this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 21:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599628#M510516</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2018-04-23T21:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599629#M510517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now the closet to integration we have is the following. We are working on a More integrated approac but can’t discuss futures here in the forum. Please get your use case and opportunity info to the ISE product management team thru the sales channel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;A class="jive-link-wiki-small" data-containerid="5301" data-containertype="14" data-objectid="77607" data-objecttype="102" href="https://communities.cisco.com/docs/DOC-77607"&gt;https://communities.cisco.com/docs/DOC-77607&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;We will also evaluate what you have here to see if there is an approach with AD but right now but I don’t understand how you are seeing this work&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 11:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599629#M510517</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-04-24T11:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599630#M510518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response Jason, much like the workflow and authentication policy when checking the SAN attribute for ISE provisioned certificates (where SAN=Calling-station-id), i was hoping for an authorization profile that can provide a dynamic attribute versus static attribute where the ascii value can be an attribute in AD. Here is the video that shows an example of authentication work flow - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-74213"&gt;Dynamic Attribute with ISE: MAC Address Matching&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basically looking for this return attribute - &lt;/P&gt;&lt;P&gt;cisco-av-pair=psk=$ADattributevalue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 19:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599630#M510518</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2018-04-24T19:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599631#M510519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;like something like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="BRKSEC-3699.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/116703_BRKSEC-3699.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 20:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599631#M510519</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-04-24T20:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599632#M510520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes sir, thats what i am looking for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 22:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599632#M510520</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2018-04-24T22:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599633#M510521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me know if this works out for you maybe we can share some knowledge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 23:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599633#M510521</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-04-24T23:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599634#M510522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, that is the model i am looking for, I guess we will need to lab this out and see what we can come up with. I looked at the document you provided, is there a way where we can leverage API integration so that when a device registers through an external API that the description can be leveraged much like the example you brought up? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device registers using an external API integration + ISE then create a random attribute and injects that inside the custom attribute we create for the endpoint?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 23:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599634#M510522</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2018-04-24T23:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599635#M510523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you should be able to do that with api integration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 00:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599635#M510523</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-04-25T00:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity PSK Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599636#M510524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far so good, we are able to send the custom attribute with the API and even update existing records or create new ones. The customer is working on their end to code the webtop but this looks very similar to the DPSK feature that we were looking for. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we get it final, we can sync up and share notes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Tarik A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 03:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-psk-questions/m-p/3599636#M510524</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2018-05-02T03:27:00Z</dc:date>
    </item>
  </channel>
</rss>

