<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SGT mapping to pxGrid learned users (Citrix TS agent example) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4565084#M573247</link>
    <description>&lt;P&gt;Yes, there is a REST API to map an IP:port to a Username for virtual desktop environments or terminal services for Passive IDentity.&amp;nbsp; See&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31.html" target="_self"&gt;Cisco Identity Services Engine Passive Identity Connector Administrator Guide, Release 3.1&lt;/A&gt; &amp;gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31/pic_admin31_chapter_011.html" target="_blank" rel="noopener"&gt;Providers&lt;/A&gt; &amp;gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31/pic_admin31_chapter_011.html#reference_637B4FC473F247249AD42888125FA5D0" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;API Calls&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;SGT represent a security group. The security group can represent any group of user or endpoints - it is up to you own how you define it.&amp;nbsp;&amp;nbsp; Typically ISE assigns an SGT based on an 802.1X Authentication but can be from any ISE Authorization Rule.&lt;/P&gt;
&lt;P&gt;The terminal service or VDI system needs to send this information to ISE in order for it to propogate the information to a Firewall or WSA or other pxGrid Client.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 00:10:54 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-03-07T00:10:54Z</dc:date>
    <item>
      <title>SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/3810654#M484772</link>
      <description>&lt;P&gt;Dear Colleagues,&lt;/P&gt;
&lt;P&gt;I learned yesterday that our Terminal Services agent actually CAN put 'IP:port«»user' mapping data into pxGrid and WSA 11.8 is going to be able to read and use that data along AD group info taken through pxGrid 2.0. At least as far as I understood from the CX NPI training.&lt;/P&gt;
&lt;P&gt;However as far as I understood SGT is not mapped to the user. I know that in TrustSec SGT can only be mapped to IP. But if the customer is using SGT aware Firewall or WSA Access rules where SGT is queried along with the user anyway, could we make ISE possible to add SGTs to these TS Agent published mappings somehow? Or could we make TS agent able to handle multiple SGTs and IP addresses and PAT the Virtual Desktop to the IP:SGT pair based on user attributes.&lt;/P&gt;
&lt;P&gt;It might be a roadmap item to consider.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Istvan&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 09:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/3810654#M484772</guid>
      <dc:creator>Istvan Segyik</dc:creator>
      <dc:date>2019-02-27T09:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/3814443#M484778</link>
      <description>&lt;P&gt;Istvan, very good question. As you said we are working towards a solution or rather I call an agent which would work with MS term sever or Citrix Environment where multiple users coming with a single IP would be allocated an IP per user from the proposed agent. ISE can then assign the SGTs for the users and in turn share those IP-SGT mappings via SXP and pxGrid to the rest of the network.&lt;/P&gt;
&lt;P&gt;As far as timelines are concerned I cannot provide an estimate but it is in development.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 18:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/3814443#M484778</guid>
      <dc:creator>kthumula</dc:creator>
      <dc:date>2019-03-05T18:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4542264#M572488</link>
      <description>&lt;P&gt;Hi kthumula,&lt;/P&gt;&lt;P&gt;is there any news on this topic?&lt;/P&gt;&lt;P&gt;Is this already possible?&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 11:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4542264#M572488</guid>
      <dc:creator>netadmin111112</dc:creator>
      <dc:date>2022-01-30T11:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4542322#M572489</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp;&amp;gt;....&amp;nbsp;I cannot provide an estimate but it&lt;U&gt;&lt;STRONG&gt; is in development.&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 15:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4542322#M572489</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-01-30T15:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4562370#M573078</link>
      <description>&lt;P&gt;Do you need someone for testing?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 18:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4562370#M573078</guid>
      <dc:creator>wagner</dc:creator>
      <dc:date>2022-03-02T18:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: SGT mapping to pxGrid learned users (Citrix TS agent example)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4565084#M573247</link>
      <description>&lt;P&gt;Yes, there is a REST API to map an IP:port to a Username for virtual desktop environments or terminal services for Passive IDentity.&amp;nbsp; See&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31.html" target="_self"&gt;Cisco Identity Services Engine Passive Identity Connector Administrator Guide, Release 3.1&lt;/A&gt; &amp;gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31/pic_admin31_chapter_011.html" target="_blank" rel="noopener"&gt;Providers&lt;/A&gt; &amp;gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/pic_admin_guide/pic_admin31/pic_admin31_chapter_011.html#reference_637B4FC473F247249AD42888125FA5D0" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;API Calls&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;SGT represent a security group. The security group can represent any group of user or endpoints - it is up to you own how you define it.&amp;nbsp;&amp;nbsp; Typically ISE assigns an SGT based on an 802.1X Authentication but can be from any ISE Authorization Rule.&lt;/P&gt;
&lt;P&gt;The terminal service or VDI system needs to send this information to ISE in order for it to propogate the information to a Firewall or WSA or other pxGrid Client.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 00:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-mapping-to-pxgrid-learned-users-citrix-ts-agent-example/m-p/4565084#M573247</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-03-07T00:10:54Z</dc:date>
    </item>
  </channel>
</rss>

