<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Purge Default Behaviour in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604414#M528074</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a query from customer about Endpoint Purge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This endpoint purge schedule is enabled by default. Cisco ISE, by default, deletes endpoints and registered devices that are older than 30 days from following link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We advised customer that the ISE default endpoint purge is set to purge endpoints and registered devices that are older than 30 days from above information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer has asked confirmation for “older than 30 days”. Does this mean inactive for 30 days rather than endpoints registered 30 days ago?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone please help on this query?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Aug 2017 06:52:44 GMT</pubDate>
    <dc:creator>chbudima</dc:creator>
    <dc:date>2017-08-01T06:52:44Z</dc:date>
    <item>
      <title>Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604414#M528074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a query from customer about Endpoint Purge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This endpoint purge schedule is enabled by default. Cisco ISE, by default, deletes endpoints and registered devices that are older than 30 days from following link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We advised customer that the ISE default endpoint purge is set to purge endpoints and registered devices that are older than 30 days from above information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer has asked confirmation for “older than 30 days”. Does this mean inactive for 30 days rather than endpoints registered 30 days ago?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone please help on this query?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 06:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604414#M528074</guid>
      <dc:creator>chbudima</dc:creator>
      <dc:date>2017-08-01T06:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604415#M528075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html#concept_0776B37A2C3542189950F5DFB1961FA2" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html#concept_0776B37A2C3542189950F5DFB1961FA2"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.2 - Setup Adaptive Network Control [Cisco Identity Serv…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2 class="topictitle2" style="margin-top: 20px; margin-bottom: 8px; font-weight: 400; font-size: 2.4rem; font-family: CiscoSans, Arial, sans-serif; color: #39393b;"&gt;Endpoints Purge Settings&lt;/H2&gt;&lt;P style="margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;You can define the Endpoint Purge Policy by configuration rules based on identity groups and other conditions using &lt;SPAN class="menucascade" style="font-style: inherit; font-size: inherit; font-family: inherit;"&gt;&lt;SPAN class="uicontrol" style="font-style: inherit; font-weight: bold; font-size: inherit; font-family: inherit;"&gt;Administration&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol" style="font-style: inherit; font-weight: bold; font-size: inherit; font-family: inherit;"&gt;Identity Management&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol" style="font-style: inherit; font-weight: bold; font-size: inherit; font-family: inherit;"&gt;Settings&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol" style="font-style: inherit; font-weight: bold; font-size: inherit; font-family: inherit;"&gt;Endpoint Purge&lt;/SPAN&gt;&lt;/SPAN&gt;. You can choose not to purge specified endpoints and to purge endpoints based on selected profiling conditions.&lt;/P&gt;&lt;P style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;You can schedule an endpoint purge job. This endpoint purge schedule is enabled by default. Cisco ISE, by default, deletes endpoints and registered devices that are older than 30 days. The purge job runs at 1 AM every day based on the time zone configured in the Primary PAN.&lt;/P&gt;&lt;P style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;The following are some of the conditions with examples you can use for purging the endpoints:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_E4CA4642522D4A5EA3814456FEBDAB28" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;InactivityDays— Number of days since last profiling activity or update on endpoint.&lt;/SPAN&gt;&lt;UL style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: inherit; font-family: inherit; list-style: disc outside none;"&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_E6B809520C8D48DF8322DC96FB9A3ECF" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;This condition purges stale devices that have accumulated over time, commonly transient guest or personal devices, or retired devices. These endpoints tend to represent noise in most deployments as they are no longer active on network or likely to be seen in near future. If they do happen to connect again, then they will be rediscovered, profiled, registered, etc as needed.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_3DF2F18D7B57462E88BDD8AFC1FD91FF" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;When there are updates from endpoint, InactivityDays will be reset to 0 only if profiling is enabled.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_04020C756FDC4488B920D7B2B0540E29" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;ElapsedDays—Numbers days since object is created.&lt;/SPAN&gt;&lt;UL&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_EBCEA104EC0D4EAD90BC9AF595CA9222" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;This condition can be used for endpoints that have been granted unauthenticated or conditional access for a set time period, such as a guest or contractor endpoint, or employees leveraging webauth for network access. After the allowed connect grace period, they must be fully reauthenticated and registered.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_CAD9F9AB79DC4129A604A274EE5F7889" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;PurgeDate—Date to purge the endpoint.&lt;/SPAN&gt;&lt;UL&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;&lt;A name="concept_0776B37A2C3542189950F5DFB1961FA2__li_581260AD02AA4B22B20861E4D3C2053A" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-style: inherit; font-size: 1.4rem; font-family: inherit;"&gt;This option can be used for special events or groups where access is granted for a specific time, regardless of creation or start time. This allows all endpoints to be purged at same time. For example, a trade show, a conference, or a weekly training class with new members each week, where access is granted for specific week or month rather than absolute days/weeks/months.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 14:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604415#M528075</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T14:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604416#M528076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for sharing the information. I found this information too from configuration guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer does not have any policy configured related with InactivityDays, ElapsedDays and PurgeDate.&lt;/P&gt;&lt;P&gt;Therefore where this query comes from the customer, what is the default behavior for endpoint purge for “older than 30 days”. The query from customer with endpoint purge for “older than 30 days” meaning inactive for 30 days or endpoints registered 30 days ago?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please help on this query?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 23:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604416#M528076</guid>
      <dc:creator>chbudima</dc:creator>
      <dc:date>2017-08-01T23:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604417#M528077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't understand, do they have anything configured for a purge policy? If so what does the line say? Send a screenshot of their purge policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default rules are guest endpoints or registered endpoints are purged after 30 days (elapsed meaning after the action of them being put into the database they are removed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only time inactivity is considered is if you select inactive days&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Aug 2017 23:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604417#M528077</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-01T23:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604418#M528078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer has configured a daily purge policy for Guest Wifi User. However customer does not have a purge policy for their BYOD Wifi User.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your confirmation the default endpoint purge rule is, registered endpoints are purged after 30 days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Charles&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 00:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3604418#M528078</guid>
      <dc:creator>chbudima</dc:creator>
      <dc:date>2017-08-02T00:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3728000#M528079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I need some more details about "Inactivitydays".&lt;/P&gt;
&lt;P&gt;Actually on ise 2.3&amp;nbsp;I found two objects in dictionary to build purge conditions:&lt;/P&gt;
&lt;P&gt;ElapsedDays and Inactivedays.&lt;/P&gt;
&lt;P&gt;But I am not sure that Inactivedays is a counter of the number of days from device "last seen" event.&lt;/P&gt;
&lt;P&gt;Indeed I gave a look at a currently connected device and I saw that the two counters have the same value. Why Inactivedays attribute is not zero being the device connected?&lt;/P&gt;
&lt;P&gt;Is a 2.3 patch 3 bug?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 15:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3728000#M528079</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2018-10-18T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3812234#M528080</link>
      <description>&lt;P&gt;I know this is old, but from Jason's post above:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;When there are updates from endpoint, InactivityDays will be reset to 0 only if profiling is enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Was profiling enabled?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 02:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3812234#M528080</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2019-03-01T02:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Purge Default Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3812320#M528081</link>
      <description>&lt;P&gt;You are right.&lt;/P&gt;
&lt;P&gt;I had missed that statement in the guide. Without a license that enable profiling "Inactivedays" counter is unusable.&lt;/P&gt;
&lt;P&gt;Regard&lt;/P&gt;
&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 07:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-purge-default-behaviour/m-p/3812320#M528081</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2019-03-01T07:17:00Z</dc:date>
    </item>
  </channel>
</rss>

