<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time of Day per User Application Restriction in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457635#M530574</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE can’t control the app usage time, like Hsing said that would be MDM possibly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we can control access to the resources in the network. Either by time in the authz rules or location (with MSE 8 integration). You could assign a tag to the permissions and restrict using WSA policy what internet sites.  This tag could also restrict at the datacenter as well. This would be SGT (trustsec) tagging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could also be done with ACL or VLAN on the internal networks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Mar 2017 20:46:06 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-03-24T20:46:06Z</dc:date>
    <item>
      <title>Time of Day per User Application Restriction</title>
      <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457632#M530571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;For Customer RFP response - A customer would like to authenticate wireless users - which may be on laptops or smart devices (ipad/iphone and similar) and apply an AVC profile to a flexconnect wireless client.&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;But for certain times of the day, then restrict the users only to certain applications.&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;The example being schools.&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;During lesson time they want to allow to application for classroom use and block internet, but during breaks, potentially allow internet and other applications, but then restrict when back in class sessions again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;Is there an easy method within ISE to achieve this?&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;If you authenticate and have AAA override with AVC profiles pushed to clients, then would you need to force a re-auth, in-order for any new avc profiles to be pushed for different times of day?&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;Or, would you need to have a constant posture assessment on to evaluate client devices an allow apps?&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;Or, could you allow applications on a per location basis - therefore, if in classroom, allow app's x,y,z or if not in classroom allow apps a,b,c ? - assume you would need pretty good location capability for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;open to any suggestions of a good approach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;Many thanks,&lt;/P&gt;&lt;P style="font-size: 15px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2017 20:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457632#M530571</guid>
      <dc:creator>Jason Tyler</dc:creator>
      <dc:date>2017-03-24T20:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Time of Day per User Application Restriction</title>
      <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457633#M530572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are the applications actual apps on the device or are they applications they access in the internal environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meaning if we blocked internet in the network (using authz rules) and allowed internal site access while in the classroom would this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or they want to restrict actual apps from usage on the Mobile devices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2017 20:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457633#M530572</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-03-24T20:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Time of Day per User Application Restriction</title>
      <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457634#M530573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that there could be a combination of both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, for example, they may wish to block youtube, for example, during lesson time, but allow during breaks.&lt;/P&gt;&lt;P&gt;But also, allow access to apps on the devices themselves whilst in class, but not when during break.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies I cannot give you more information as yet, as this was a very quick question during an RFP conversation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2017 20:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457634#M530573</guid>
      <dc:creator>Jason Tyler</dc:creator>
      <dc:date>2017-03-24T20:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Time of Day per User Application Restriction</title>
      <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457635#M530574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE can’t control the app usage time, like Hsing said that would be MDM possibly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we can control access to the resources in the network. Either by time in the authz rules or location (with MSE 8 integration). You could assign a tag to the permissions and restrict using WSA policy what internet sites.  This tag could also restrict at the datacenter as well. This would be SGT (trustsec) tagging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could also be done with ACL or VLAN on the internal networks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2017 20:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457635#M530574</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-03-24T20:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Time of Day per User Application Restriction</title>
      <link>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457636#M530575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No Problems Jason, this is as i suspected, but just wanted to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;j&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2017 20:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-of-day-per-user-application-restriction/m-p/3457636#M530575</guid>
      <dc:creator>Jason Tyler</dc:creator>
      <dc:date>2017-03-24T20:51:49Z</dc:date>
    </item>
  </channel>
</rss>

