<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE reporting questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459583#M522192</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Sep 2017 04:32:50 GMT</pubDate>
    <dc:creator>jonbrown</dc:creator>
    <dc:date>2017-09-08T04:32:50Z</dc:date>
    <item>
      <title>ISE reporting questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459580#M522184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings, customer is looking for the following information from ISE, working with the partner we came up with the text in red. Can you confirm we've vetted out all the possibilities? There may be other software (like Prime or a syslog server) which gives them information, but they want it from ISE so they can react.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif; color: black;"&gt;ISE configuration is removed from a network switch port that was ISE enabled previously&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif;"&gt;– &lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: red; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;ISE cannot provide any report/alert of this event. Is this on the roadmap?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif;"&gt;A computer has plugged into a port not configured for ISE -&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: red; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;ISE cannot provide any report/alert of this event. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif;"&gt;A non-corporate asset has been plugged into an ISE port. &lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #ff2600; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Can be done but may give you false positives. (Customer has devices that don't support certificates.) I believe we could create a rule to check if the device is part of an AD group?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif; color: black;"&gt;A generated monthly report of all ports that do not have ISE enabled&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Calibri, sans-serif;"&gt;. &lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #ff2600; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Can be done in real time by ISE, could run an operations report for device status. Would show ports without an ISE configuration as NA. see attachment. I think this requires SNMP for ISE to query the switch ports for this. Can this report be automated to run monthly?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt; jb&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 01:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459580#M522184</guid>
      <dc:creator>jonbrown</dc:creator>
      <dc:date>2017-09-06T01:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE reporting questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459581#M522186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jb, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the answers inline ( blue) for the response I received from the team on this query . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="color: black;"&gt;ISE configuration is removed from a network switch port that was ISE enabled previously&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d;"&gt;–&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="color: red;"&gt;ISE cannot provide any report/alert of this event. Is this on the roadmap?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background: white;"&gt;&lt;SPAN style="color: #5b9bd5;"&gt;There are no such reports for this event. But we can go to troubleshooting page and check the configuration for the network switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background: white;"&gt;&lt;SPAN style="color: #5b9bd5;"&gt;Please check with the PM team about the roadmap for this,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="color: #3d3d3d;"&gt;A computer has plugged into a port not configured for ISE -&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="color: red;"&gt;ISE cannot provide any report/alert of this event.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background: white;"&gt;&lt;SPAN style="color: #5b9bd5;"&gt;True, ISE cannot provide any report for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="color: #3d3d3d;"&gt;A non-corporate asset has been plugged into an ISE port.&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="color: #ff2600;"&gt;Can be done but may give you false positives. (Customer has devices that don't support certificates.) I believe we could create a rule to check if the device is part of an AD group?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background: white;"&gt;&lt;SPAN style="color: #5b9bd5;"&gt;BYOD flow is there. And we do have couple of reports in BYOD section in the reports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="color: black;"&gt;A generated monthly report of all ports that do not have ISE enabled&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d;"&gt;.&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="color: #ff2600;"&gt;Can be done in real time by ISE, could run an operations report for device status. Would show ports without an ISE configuration as NA. see attachment. I think this requires SNMP for ISE to query the switch ports for this. Can this report be automated to run monthly?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this particular report we don’t have option to schedule it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459581#M522186</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-09-06T07:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE reporting questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459582#M522189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please keep in mind that ISE is not to use for configuring or auditing of the configurations on network devices. You should seek other tools, such as PI, DNA-C, or &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-64597"&gt;ISE Deployment Assistant (IDA)&lt;/A&gt; to do that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 15:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459582#M522189</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-07T15:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE reporting questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459583#M522192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 04:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reporting-questions/m-p/3459583#M522192</guid>
      <dc:creator>jonbrown</dc:creator>
      <dc:date>2017-09-08T04:32:50Z</dc:date>
    </item>
  </channel>
</rss>

