<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unquarantine Endpoint in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unquarantine-endpoint-in-ise/m-p/3592825#M530602</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have integrated Firepower with ISE using PXGRID. I have certain rules in Firepower and if endpoint hits the rule it will send quarantine action to ISE for that endpoint. ISE is quarantining the endpoint and denying all the access. I am using ISE 2.0 version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have following questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is there any way to unquarantine the endpoint automatically?&lt;/P&gt;&lt;P&gt;2. where I can see all the quarantine mac-addresses in ISE? Other-than reports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Mar 2017 13:39:15 GMT</pubDate>
    <dc:creator>meetneelesh79</dc:creator>
    <dc:date>2017-03-23T13:39:15Z</dc:date>
    <item>
      <title>Unquarantine Endpoint in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unquarantine-endpoint-in-ise/m-p/3592825#M530602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have integrated Firepower with ISE using PXGRID. I have certain rules in Firepower and if endpoint hits the rule it will send quarantine action to ISE for that endpoint. ISE is quarantining the endpoint and denying all the access. I am using ISE 2.0 version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have following questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is there any way to unquarantine the endpoint automatically?&lt;/P&gt;&lt;P&gt;2. where I can see all the quarantine mac-addresses in ISE? Other-than reports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2017 13:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unquarantine-endpoint-in-ise/m-p/3592825#M530602</guid>
      <dc:creator>meetneelesh79</dc:creator>
      <dc:date>2017-03-23T13:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unquarantine Endpoint in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unquarantine-endpoint-in-ise/m-p/3592826#M530603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Neelesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can setup an Unquarantine Correlation in Firepower to trigger unquarantine actions : &lt;A href="https://community.cisco.com/docs/DOC-68293"&gt;How To: Rapid Threat Containment (RTC) with Cisco FireSIGHT and ISE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an older doc than Firepower, but the policies and configurations are the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reports are the only way to see the endpoints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:jeppich@cisco.com"&gt;jeppich@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2017 15:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unquarantine-endpoint-in-ise/m-p/3592826#M530603</guid>
      <dc:creator>jeppich</dc:creator>
      <dc:date>2017-03-23T15:38:04Z</dc:date>
    </item>
  </channel>
</rss>

