<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regional Admin delegation for ISE distributed Setup in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3749089#M542803</link>
    <description>&lt;P&gt;&amp;nbsp;Many Thanks Arne.&lt;/P&gt;
&lt;P&gt;Babacar&lt;/P&gt;</description>
    <pubDate>Mon, 19 Nov 2018 08:23:31 GMT</pubDate>
    <dc:creator>bawagne</dc:creator>
    <dc:date>2018-11-19T08:23:31Z</dc:date>
    <item>
      <title>Regional Admin delegation for ISE distributed Setup</title>
      <link>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3747184#M542801</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a customer that intend to have a distributed deployments in several regions.&lt;/P&gt;
&lt;P&gt;Each region will have a group of 2 PSNs.&lt;/P&gt;
&lt;P&gt;They want to delegate admin per region.&lt;/P&gt;
&lt;P&gt;So i want to understand down to which level can we delegate the admin right; Policy for each region? PSN for each? Data Logs for region? NAD for each region?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have gone through the below document which gives details on how to give different admin right on the PAN not really my use case which more base a delegation based on location.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0101.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0101.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Babacar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3747184#M542801</guid>
      <dc:creator>bawagne</dc:creator>
      <dc:date>2019-03-11T08:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Regional Admin delegation for ISE distributed Setup</title>
      <link>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3747244#M542802</link>
      <description>&lt;P&gt;If you intend on having multiple PSN's spread over multiple regions, but the entire deployment managed by two PAN nodes, then I am pretty sure you cannot perform RBAC (Role Based Access Control) down to PSN level.&amp;nbsp; I have only seen menu options that can be customised, and then the data access (read/write type of access) - but this applies to particular functions that span across all PSN's.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're thinking of how Prime Infrastructure does its hierarchical access using Operations Centre, and then using Virtual-Domains etc.&amp;nbsp; That concept does not apply to ISE.&amp;nbsp; I would hazard a guess and say you'd need to deploy multiple PAN/MnT/PSN pairs all over the place if you want that sort of role based segregation.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 10:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3747244#M542802</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-11-15T10:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regional Admin delegation for ISE distributed Setup</title>
      <link>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3749089#M542803</link>
      <description>&lt;P&gt;&amp;nbsp;Many Thanks Arne.&lt;/P&gt;
&lt;P&gt;Babacar&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 08:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3749089#M542803</guid>
      <dc:creator>bawagne</dc:creator>
      <dc:date>2018-11-19T08:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Regional Admin delegation for ISE distributed Setup</title>
      <link>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3749090#M542804</link>
      <description>&lt;P&gt;&amp;nbsp;Many Thanks Arne.&lt;/P&gt;
&lt;P&gt;Babacar&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 08:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/regional-admin-delegation-for-ise-distributed-setup/m-p/3749090#M542804</guid>
      <dc:creator>bawagne</dc:creator>
      <dc:date>2018-11-19T08:23:57Z</dc:date>
    </item>
  </channel>
</rss>

