<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE: question to Fetch groups&amp;quot; &amp; &amp;quot;Fetch attributes&amp;quot; used by ISE in the ODBC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536754#M529861</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has maybe anybody experience in migration from ACS to ISE and the following problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;".. Actual we are running an ACS 4.2 connected to an Oracle DB.&lt;/P&gt;&lt;P&gt;The idea is (and we need a solution asap) is to connect ISE to the same Oracle DB using different stored procedures.&lt;/P&gt;&lt;P&gt;There is a complex process running to bring the needed data into the Oracle DB (means that it is impossible to change something on the DB layout).&lt;/P&gt;&lt;P&gt;The team spent a lot of time reading docs on cisco.com looking for a clear description about stored procedures etc. but it seems that the given examples are incomplete or wrong.&lt;/P&gt;&lt;P&gt;I kindly ask you to provide a solution as soon as possible. If you need further information feel free to call me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;some technical details:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client (PC) authentication and authorization (Vlan assignment) was done with ACS 4.2 and external data source oracle using a stored procedure (as defined in the ACS manual).&lt;/P&gt;&lt;P&gt;Now we migrate to ISE and realize, that only half of the procedure (authentication) is working. For the assignment of users to groups (authorization) we have to use a different procedure which is in best case vaguely described.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is now needed is the exact documentation of the interface ("Fetch groups" &amp;amp; "Fetch attributes" used by ISE in the ODBC Identity source, so we can program the oracle procedure accordingly.&lt;/STRONG&gt;..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp; uwe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 May 2017 16:28:36 GMT</pubDate>
    <dc:creator>ujundt@cisco.com</dc:creator>
    <dc:date>2017-05-04T16:28:36Z</dc:date>
    <item>
      <title>ISE: question to Fetch groups" &amp; "Fetch attributes" used by ISE in the ODBC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536754#M529861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has maybe anybody experience in migration from ACS to ISE and the following problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;".. Actual we are running an ACS 4.2 connected to an Oracle DB.&lt;/P&gt;&lt;P&gt;The idea is (and we need a solution asap) is to connect ISE to the same Oracle DB using different stored procedures.&lt;/P&gt;&lt;P&gt;There is a complex process running to bring the needed data into the Oracle DB (means that it is impossible to change something on the DB layout).&lt;/P&gt;&lt;P&gt;The team spent a lot of time reading docs on cisco.com looking for a clear description about stored procedures etc. but it seems that the given examples are incomplete or wrong.&lt;/P&gt;&lt;P&gt;I kindly ask you to provide a solution as soon as possible. If you need further information feel free to call me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;some technical details:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client (PC) authentication and authorization (Vlan assignment) was done with ACS 4.2 and external data source oracle using a stored procedure (as defined in the ACS manual).&lt;/P&gt;&lt;P&gt;Now we migrate to ISE and realize, that only half of the procedure (authentication) is working. For the assignment of users to groups (authorization) we have to use a different procedure which is in best case vaguely described.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is now needed is the exact documentation of the interface ("Fetch groups" &amp;amp; "Fetch attributes" used by ISE in the ODBC Identity source, so we can program the oracle procedure accordingly.&lt;/STRONG&gt;..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp; uwe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 16:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536754#M529861</guid>
      <dc:creator>ujundt@cisco.com</dc:creator>
      <dc:date>2017-05-04T16:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: question to Fetch groups" &amp; "Fetch attributes" used by ISE in the ODBC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536755#M529862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to send result code of '0' and the list of groups that the user is member of or all the attributes that user record holds. The admin guide should provide what you need:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#id_10025" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#id_10025"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.1 - Manage Users and External Identity Sources [Cisco Ide…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, sample procedures shown for MS SQL &amp;amp; Postgres SQL:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200544-Configure-ISE-2-1-with-MS-SQL-using-ODBC.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200544-Configure-ISE-2-1-with-MS-SQL-using-ODBC.html"&gt;Configure ISE 2.1 with MS SQL using ODBC - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200644-Configure-ODBC-on-ISE-2-1-with-PostgreSQ.html#anc8" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200644-Configure-ODBC-on-ISE-2-1-with-PostgreSQ.html#anc8"&gt;Configure ODBC on ISE 2.1 with PostgreSQL - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hosuk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 16:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536755#M529862</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-05-04T16:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: question to Fetch groups" &amp; "Fetch attributes" used by ISE in the ODBC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536756#M529863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sample functions or stored procedures for each supported DBMS vendors are on ISE admin web UI, too.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-05-05 at 7.23.35 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/107006_Screen Shot 2017-05-05 at 7.23.35 PM.png" style="height: 231px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 May 2017 22:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-question-to-fetch-groups-quot-quot-fetch-attributes-quot/m-p/3536756#M529863</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-06T22:02:36Z</dc:date>
    </item>
  </channel>
</rss>

