<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Per-Device Identity PSK in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3678967#M511224</link>
    <description>&lt;P&gt;Snippet of config is shared in BRKSEC-3697 session from Cisco Live &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=brksec-3697#/session/1509501680902001PsTe" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also received Community post with sample config details &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-amp-wlc-wpa2-psk-wlan-per-device-passphrase-ipsk/ta-p/3644425" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Aug 2018 08:58:01 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-08-01T08:58:01Z</dc:date>
    <item>
      <title>Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521814#M511217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a recommended ISE configuration for per-device Identity PSK at large scale?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working on a wireless ISE design.&amp;nbsp; It will entail numerous consumer and IoT devices in a university setting.&amp;nbsp; The consumer and IoT devices are managed by individuals, not centrally.&amp;nbsp; An individual might have multiple devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a recommended configuration doesn't exist, I spot-tested the following configuration in my lab:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For the endpoint, create a custom attribute for the device's PSK.&amp;nbsp; (psk=&amp;lt;unique key&amp;gt;)&lt;/LI&gt;&lt;LI&gt;Create a new Authorization Profile.&lt;/LI&gt;&lt;LI&gt;Within the Authorization Profile, create two advanced attributes:&lt;OL&gt;&lt;LI&gt;Cisco:cisco-av-pair = psk-mode=ascii&lt;/LI&gt;&lt;LI&gt;Cisco:cisco-av-pair = Endpoints:&amp;lt;custom endpoint attribute&amp;gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Create a new Authorization Policy with appropriate match conditions.&lt;/LI&gt;&lt;LI&gt;Assign newly created Authorization Profile as the result.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The university would have to create a custom device registration portal.&amp;nbsp; The portal would generate one unique PSK for the student, and register the MAC address of the IoT device.&amp;nbsp; The ISE ERS API could be used to bulk create/update the endpoints on ISE as a scheduled job.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 21:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521814#M511217</guid>
      <dc:creator>Jonathan Grim</dc:creator>
      <dc:date>2018-03-28T21:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521815#M511218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE 2.2+ is supporting custom endpoint attributes in authorization profiles. What you have is pretty much the same as recommended.&lt;/P&gt;&lt;P&gt;Please note a know issue -- CSCvd40908&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 04:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521815#M511218</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-29T04:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521816#M511219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very nice, if you have anymore information on how you setup your controller, some screenshots and more detail to share that will help others!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521816#M511219</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-29T15:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521817#M511220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can certainly add screen shots of WLC and ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick question...&amp;nbsp; In My Devices Portal, is there a way to add custom fields to the portal, and link it to an endpoint custom attribute?&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521817#M511220</guid>
      <dc:creator>Jonathan Grim</dc:creator>
      <dc:date>2018-03-29T18:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521818#M511221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is not, please reach out thru sales channel to our PM that is covering this feature, his name is Ameet Kulkarni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521818#M511221</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-29T18:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521819#M511222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that is the method we tested internally using custom attribute.&amp;nbsp; I can share config used, but it is essentially what is shown above. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no option with current My Devices to populate custom attributes.&amp;nbsp; We are well aware of the potential but cannot discuss roadmap in this forum. Customers/account team can reach out directly to account team to solicit additional details.&amp;nbsp; It is certainly possible to customize custom attributes using ERS API, either directly or part of a custom portal to populate the required values per endpoint.&amp;nbsp; We have other customers doing this already.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 14:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3521819#M511222</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-03-30T14:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3678857#M511223</link>
      <description>&lt;BR /&gt;Pls share the more details document for configuration of per user/per device conf.&lt;BR /&gt;&lt;BR /&gt;so that we can configure it, in our network as well.&lt;BR /&gt;&lt;BR /&gt;Its a nice option.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 01 Aug 2018 06:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3678857#M511223</guid>
      <dc:creator>prashantk</dc:creator>
      <dc:date>2018-08-01T06:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Device Identity PSK</title>
      <link>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3678967#M511224</link>
      <description>&lt;P&gt;Snippet of config is shared in BRKSEC-3697 session from Cisco Live &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=brksec-3697#/session/1509501680902001PsTe" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also received Community post with sample config details &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-amp-wlc-wpa2-psk-wlan-per-device-passphrase-ipsk/ta-p/3644425" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 08:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-device-identity-psk/m-p/3678967#M511224</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-08-01T08:58:01Z</dc:date>
    </item>
  </channel>
</rss>

