<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Distributed - PSNs associated to Specific RSA Servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518436#M510679</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul is correct that PSN node groups are not available as authentication policy conditions and they are more for ISE profiling replications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you meant network devices in the same network device groups use the same sets of PSNs, then you may use the network device grouping as the authentication policy conditions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Apr 2018 03:17:26 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-04-25T03:17:26Z</dc:date>
    <item>
      <title>ISE Distributed - PSNs associated to Specific RSA Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518434#M510675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Hey guys &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Quick question. &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;I have been reading about this but I would like to get confirmation as it gets quite confusing lol &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Anyway, my client has an ISE distributed env based on Dedicated PAN, Mnt and PSNs&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;They will be using many RSA servers as external identity sources.&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Because of the distribution of the PSNs group of network devices (NAD group)&amp;nbsp;&amp;nbsp; will be using specific PSNs and other group of NADs other&amp;nbsp; PSNs.&amp;nbsp; &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Question:&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;—————&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;For specific groups of devices (NAD grouped per location for example) can they use a specific RSA server? As &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;PSN1—RSA1 primary &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |___RSA2 sec&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;PSN2—RSA2 primary &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |___RSA1 sec&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;This seems possible using rule based authentication policies in ISE. &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;However although it seems to be based on specific ISE&amp;nbsp; attributes only part of the ISE dictionary&amp;nbsp; &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;It seems we can group PSN together as a mode group.&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;So in this case I can def configure each NAD to point to specific “node group” then using rule based authentications asking these Node groups (based on device IP or device network group or location) to use a specific RSA servers.&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;If you could chime in I would appreciate. &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Thank you &lt;/P&gt;&lt;P style="color: #000000; font-family: -webkit-standard; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;IMG alt="image1.jpeg" class="jive-image" src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2018 21:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518434#M510675</guid>
      <dc:creator>Samuel Vuillaume</dc:creator>
      <dc:date>2018-04-17T21:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed - PSNs associated to Specific RSA Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518435#M510677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you can use node groups in Auth criteria, but just use the PSN hostname attribute:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/116614_Capture.JPG" style="height: 188px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 16:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518435#M510677</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-04-18T16:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Distributed - PSNs associated to Specific RSA Servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518436#M510679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul is correct that PSN node groups are not available as authentication policy conditions and they are more for ISE profiling replications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you meant network devices in the same network device groups use the same sets of PSNs, then you may use the network device grouping as the authentication policy conditions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 03:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-psns-associated-to-specific-rsa-servers/m-p/3518436#M510679</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-25T03:17:26Z</dc:date>
    </item>
  </channel>
</rss>

