<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User movement notification in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529840#M519869</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not a capability of ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you trying to prevent?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Nov 2017 12:29:28 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-11-15T12:29:28Z</dc:date>
    <item>
      <title>User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529839#M519867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ISE server and switch environment with dot1x enabled and configured&lt;/P&gt;&lt;P&gt;Is it possible to receive email every time when user authenticates on one port then unplugs cable, plug it in another port (on the same or on the different switch) and authenticates again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, then how could i complete this?&lt;/P&gt;&lt;P&gt;Switches could send snmp traps on ISE and ISE could notify me on some alerts via email, but i can't find mac move alerts in ISE configuration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 10:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529839#M519867</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2017-11-15T10:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529840#M519869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not a capability of ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you trying to prevent?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 12:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529840#M519869</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-15T12:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529841#M519871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Trying to prevent users from moving on their own from one switch port to another one&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 12:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529841#M519871</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2017-11-15T12:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529842#M519872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is not possible ,but the main question is why users have access to the switch and unplug cables or something else . And 1 more thing i mention if they plug or unplug from one port to another you can create authorization policy in ISE always to be assosiated on Vlan you want to use ( if ports are in different VLANS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 13:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529842#M519872</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-11-15T13:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529843#M519874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a network management function and not an ISE function&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch you can restrict Mac addresses allowed I believe by first learning and only allowing that MAC address&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 13:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529843#M519874</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-15T13:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529844#M519876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not a useful solution... we have a plenty of users and they move from one office to another (with it support help - officially and without support - that's what we want to eliminate). Every user has PC and ip-phone. And also there is port-security on switch ports with maximum of 2 mac-adresses (any). I don't want to bind mac-adresses to switch ports because it will be a nightmare to administer such environment with officially migrating users. And that's why i'm looking for another solution. &lt;/P&gt;&lt;P&gt;If it's not an ISE then what should it be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 14:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529844#M519876</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2017-11-15T14:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529845#M519879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like the others said, this is not a feature in ISE. Please investigate it on Cisco IOS platform support. It might be possible to use EEM (&lt;A href="https://supportforums.cisco.com/t5/network-infrastructure-documents/cisco-eem-basic-overview-and-sample-configurations/ta-p/3148479"&gt;Cisco EEM Basic Overview and Sample Con... - Cisco Support Community&lt;/A&gt;) and Cisco Prime Infrastructure or Cisco DNA Center might help in deploying the scripts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 16:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529845#M519879</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-15T16:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529846#M519880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The requirement doesn’t make a lot of sense, but I think you can do it with something like Splunk by correlating logs and alerting based on specific rules.  Why does it matter if they move as long as they get the same access to the network anywhere they connect?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 17:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529846#M519880</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-11-15T17:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: User movement notification</title>
      <link>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529847#M519882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 07:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-movement-notification/m-p/3529847#M519882</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2017-11-16T07:39:48Z</dc:date>
    </item>
  </channel>
</rss>

