<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE automation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-automation/m-p/4142553#M562558</link>
    <description>&lt;P&gt;We currently use ISE for our anyconnect users. Depending on the user configuration and due to an infosec requirement we need to create an individual AuthZ profile with its own DACL and a new rule in a policy that essentially identifies the user and applies the AuthZ specific to them&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’d like to automate this process but I cannot find anything in the API documentation that suggests it is possible right now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do people know of a way to create AuthZ, DACL and a AuthZ policy rule in an automated way?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Are people just not automating ISE configuration all that much?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Using ISE 2.4 currently&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2020 16:39:36 GMT</pubDate>
    <dc:creator>Northy</dc:creator>
    <dc:date>2020-08-27T16:39:36Z</dc:date>
    <item>
      <title>ISE automation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-automation/m-p/4142553#M562558</link>
      <description>&lt;P&gt;We currently use ISE for our anyconnect users. Depending on the user configuration and due to an infosec requirement we need to create an individual AuthZ profile with its own DACL and a new rule in a policy that essentially identifies the user and applies the AuthZ specific to them&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’d like to automate this process but I cannot find anything in the API documentation that suggests it is possible right now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do people know of a way to create AuthZ, DACL and a AuthZ policy rule in an automated way?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Are people just not automating ISE configuration all that much?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Using ISE 2.4 currently&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 16:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-automation/m-p/4142553#M562558</guid>
      <dc:creator>Northy</dc:creator>
      <dc:date>2020-08-27T16:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE automation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-automation/m-p/4142568#M562560</link>
      <description>&lt;P&gt;AFAIK you can utilize ISE APIs to create authz profiles, and dacls.&amp;nbsp; I have not tested this as I primarily use the APIs to manipulate groups, and endpoints.&amp;nbsp; However, If you go to your pan sdk via https://&amp;lt;PAN IP&amp;gt;:9060/ers/sdk# and go to API documentation you can see examples and this may also shed some additional light on other items you may be wishing to automate.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 17:12:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-automation/m-p/4142568#M562560</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-08-27T17:12:58Z</dc:date>
    </item>
  </channel>
</rss>

