<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: From ISE identity management, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4586248#M573885</link>
    <description>&lt;P&gt;&amp;gt; &lt;EM&gt;Does Endpoint Group with name "BLACKLIST" exists by default in ISE?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Yes but it was changes in ISE 3.0 I believe to BLOCK LIST. You may create your own group to do the same thing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;Can we remove an endpoint from blacklist endpoint group? If yes, which APIs i can use?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Yes. Delete the endpoint or change it's endpoint group. Which API resource you use depends on your approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;Can i search endpoints by ip-address via APIs and get their mac-addresses&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Please see the &lt;A href="https://developer.cisco.com/docs/identity-services-engine/latest/#!introduction-to-the-monitoring-rest-api" target="_self"&gt;Monitoring REST APIs&lt;/A&gt; for endpoint and IP based queries. You cannot do such a query for all known ISE endpoints today.&lt;/P&gt;
&lt;PRE&gt;Session Counters&lt;BR /&gt;https://ise/admin/API/mnt/Session/ActiveCount&lt;BR /&gt;https://ise/admin/API/mnt/Session/PostureCount&lt;BR /&gt;https://ise/admin/API/mnt/Session/ProfilerCount&lt;/PRE&gt;
&lt;PRE&gt;Session Lists&lt;BR /&gt;https://ise/admin/API/mnt/Session/ActiveList&lt;BR /&gt;https://ise/admin/API/mnt/Session/AuthList/{options}&lt;/PRE&gt;
&lt;PRE&gt;Session Attributes&lt;BR /&gt;https://ise/admin/API/mnt/Session/MACAddress/{mac}&lt;BR /&gt;https://ise/admin/API/mnt/Session/UserName/{username}&lt;BR /&gt;https://ise/admin/API/mnt/Session/IPAddress/{nas-ip}&lt;BR /&gt;https://ise/admin/API/mnt/Session/Active/SessionID/{audit-session-id}/0&lt;/PRE&gt;
&lt;PRE&gt;Others&lt;BR /&gt;https://ise/admin/API/mnt/Version&lt;BR /&gt;https://ise/admin/API/mnt/FailureReasons&lt;BR /&gt;https://ise/admin/API/mnt/AuthStatus/MACAddress/{mac}/{seconds}/{records}&amp;gt;/All&lt;BR /&gt;https://ise/admin/API/mnt/AcctStatusTT/MACAddress/{mac}/{seconds}&lt;BR /&gt;https://ise/admin/API/mnt/CoA/Reauth/{psn}/{mac}/{reauthtype}/{nas-ip}/{dst-ip}&lt;BR /&gt;https://ise/admin/API/mnt/CoA/Disconnect/{psn}/{mac}/&amp;lt;disconnecttype&amp;gt;/{nas-ip}/{dst-ip}&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; What kind of authorization rule is required to make it work?&lt;/P&gt;
&lt;P&gt;Have you looked at the ISE &lt;STRONG&gt;Default&lt;/STRONG&gt; Policy Set and the &lt;SPAN class="edited-span" contenteditable="true" data-id="policy-name-text-box"&gt;&lt;STRONG&gt;Wireless Black List&lt;/STRONG&gt;&lt;/SPAN&gt; authorization rule in ISE? Like that but you do not need to limit it to Wireless Access.&amp;nbsp; See &lt;A class="" href="https://community.cisco.com/t5/security-documents/ise-authentication-and-authorization-policy-reference/ta-p/3850472#toc-hId--2106958069" rel="nofollow noopener noreferrer" target="_blank"&gt;Static Endpoint Group(s)&lt;/A&gt; in &lt;LI-MESSAGE title="ISE Authentication and Authorization Policy Reference" uid="3850472" url="https://community.cisco.com/t5/security-documents/ise-authentication-and-authorization-policy-reference/m-p/3850472#U3850472"&gt;&lt;/LI-MESSAGE&gt; .&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse; font-size: .8em;" border="1" cellspacing="0" cellpadding="1"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Status&lt;/TH&gt;
&lt;TH&gt;Rule Name&lt;/TH&gt;
&lt;TH&gt;Conditions&lt;/TH&gt;
&lt;TH&gt;Profiles&lt;/TH&gt;
&lt;TH&gt;Security Groups&lt;/TH&gt;
&lt;TH&gt;Hits&lt;/TH&gt;
&lt;TH&gt;Actions&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center;"&gt;&lt;SPAN&gt;✔&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;Wireless Block List Default&lt;/TD&gt;
&lt;TD&gt;
&lt;TABLE style="border-style: hidden; margin: 0.2em;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;AND&lt;/TD&gt;
&lt;TD&gt;Wireless_Access&lt;BR /&gt;IdentityGroup-Name EQUALS Endpoint Identity Groups:Blocklist&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;TD&gt;Block_Wireless_Access&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Select from list&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="text-align: right;"&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="font-size: 1.5em; text-align: center;"&gt;⚙&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 08:15:18 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-04-05T08:15:18Z</dc:date>
    <item>
      <title>How to block a endpoint PC in Cisco ISE system?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449185#M573860</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Our company deployed Cisco ISE system to control PC clients access LAN.&lt;/P&gt;&lt;P&gt;I have a question:&lt;/P&gt;&lt;P&gt;I'd know a MAC address and I want to deny this MAC address to access our company LAN?&lt;/P&gt;&lt;P&gt;What step should I do it?&lt;/P&gt;&lt;P&gt;Thanks a lot !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR Frank&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449185#M573860</guid>
      <dc:creator>musikman1988</dc:creator>
      <dc:date>2020-02-21T13:10:38Z</dc:date>
    </item>
    <item>
      <title>From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449186#M573861</link>
      <description>&lt;P&gt;From ISE identity management, open Endpoints. IF endpoint is there ( search Endpoint using MAC ), select the endpoint and edit. Opt static group assignment and assign the endpoint as Blacklisted. Now from Authorization policy, make one policy like , if condition &amp;lt; blacklisted &amp;gt;&amp;nbsp; then permissions &amp;lt; deny &amp;gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2014 11:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449186#M573861</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-05-09T11:30:56Z</dc:date>
    </item>
    <item>
      <title>Hi Salodh,As before, I just</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449187#M573862</link>
      <description>&lt;P&gt;Hi Salodh,&lt;/P&gt;&lt;P&gt;As before, I just find MAC address and assign it as "BLACKLIST" group, but I didn't define "BLACKLIST" policy, I think this is the reason for my failure.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;/Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 May 2014 02:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/2449187#M573862</guid>
      <dc:creator>musikman1988</dc:creator>
      <dc:date>2014-05-10T02:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to block a endpoint PC in Cisco ISE system?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4005818#M573863</link>
      <description>&lt;P&gt;Profile the device as blacklist&lt;/P&gt;&lt;P&gt;1.2 Administration-&amp;gt;Identity management-&amp;gt;Endpoint-(searchmac)-&amp;gt;In network search Blacklisted&lt;/P&gt;&lt;P&gt;2.X &lt;SPAN&gt;Administration &amp;gt; &lt;/SPAN&gt;&lt;SPAN&gt;Identity Management &lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN&gt;Groups &lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN&gt;Endpoint Identity Groups&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;gt;Black&lt;/SPAN&gt;&lt;SPAN&gt;listed-Edit-&amp;gt;add&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_new_chapter_010101.html" target="_blank" rel="noopener"&gt;: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_new_chapter_010101.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 23:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4005818#M573863</guid>
      <dc:creator>ZacGomez</dc:creator>
      <dc:date>2020-01-02T23:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4584972#M573864</link>
      <description>&lt;P&gt;I want to achieve this use case via REST APIs. Is there any suggestion?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 10:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4584972#M573864</guid>
      <dc:creator>haseeb.shaukat</dc:creator>
      <dc:date>2022-04-04T10:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4585535#M573875</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1337297"&gt;@haseeb.shaukat&lt;/a&gt;,&amp;nbsp;please see &lt;LI-MESSAGE title="ISE ERS API Examples" uid="3622623" url="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/m-p/3622623#U3622623"&gt;&lt;/LI-MESSAGE&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: disc; margin-left: 15px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-155297388" rel="nofollow noopener noreferrer" target="_blank"&gt;Create an Endpoint Group and Assign an Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--1523074356" rel="nofollow noopener noreferrer" target="_blank"&gt;Create Endpoint Group&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId-964438477" rel="nofollow noopener noreferrer" target="_blank"&gt;Create Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You may always re-use the default Blacklist / Blocked List endpoint group in ISE.&lt;/P&gt;
&lt;P&gt;You may need to update/change/create an Authorization Rule in ISE depending on your policy sets and authorization rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 19:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4585535#M573875</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-04T19:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4586182#M573883</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;Thanks for the suggestions. I have studied APIs you referenced, but have some confusions:&lt;BR /&gt;1) Does Endpoint Group with name "BLACKLIST" exists by default in ISE? If no, creating a endpoint group with name "BLACKLIST" is suffice? I mean there is no option available to set as an action for a endpoint group e.g action=deny/allow traffic, only naming a group "BLACKLIST" is enough?&lt;BR /&gt;2) Can we remove an endpoint from blacklist endpoint group? If yes, which APIs i can use?&lt;/P&gt;&lt;P&gt;3) Can i search endpoints by ip-address via APIs and get their mac-addresses ?&lt;BR /&gt;4)&amp;nbsp; What kind of authorization rule is required to make it work?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 06:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4586182#M573883</guid>
      <dc:creator>haseeb.shaukat</dc:creator>
      <dc:date>2022-04-05T06:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4586248#M573885</link>
      <description>&lt;P&gt;&amp;gt; &lt;EM&gt;Does Endpoint Group with name "BLACKLIST" exists by default in ISE?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Yes but it was changes in ISE 3.0 I believe to BLOCK LIST. You may create your own group to do the same thing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;Can we remove an endpoint from blacklist endpoint group? If yes, which APIs i can use?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Yes. Delete the endpoint or change it's endpoint group. Which API resource you use depends on your approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;Can i search endpoints by ip-address via APIs and get their mac-addresses&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Please see the &lt;A href="https://developer.cisco.com/docs/identity-services-engine/latest/#!introduction-to-the-monitoring-rest-api" target="_self"&gt;Monitoring REST APIs&lt;/A&gt; for endpoint and IP based queries. You cannot do such a query for all known ISE endpoints today.&lt;/P&gt;
&lt;PRE&gt;Session Counters&lt;BR /&gt;https://ise/admin/API/mnt/Session/ActiveCount&lt;BR /&gt;https://ise/admin/API/mnt/Session/PostureCount&lt;BR /&gt;https://ise/admin/API/mnt/Session/ProfilerCount&lt;/PRE&gt;
&lt;PRE&gt;Session Lists&lt;BR /&gt;https://ise/admin/API/mnt/Session/ActiveList&lt;BR /&gt;https://ise/admin/API/mnt/Session/AuthList/{options}&lt;/PRE&gt;
&lt;PRE&gt;Session Attributes&lt;BR /&gt;https://ise/admin/API/mnt/Session/MACAddress/{mac}&lt;BR /&gt;https://ise/admin/API/mnt/Session/UserName/{username}&lt;BR /&gt;https://ise/admin/API/mnt/Session/IPAddress/{nas-ip}&lt;BR /&gt;https://ise/admin/API/mnt/Session/Active/SessionID/{audit-session-id}/0&lt;/PRE&gt;
&lt;PRE&gt;Others&lt;BR /&gt;https://ise/admin/API/mnt/Version&lt;BR /&gt;https://ise/admin/API/mnt/FailureReasons&lt;BR /&gt;https://ise/admin/API/mnt/AuthStatus/MACAddress/{mac}/{seconds}/{records}&amp;gt;/All&lt;BR /&gt;https://ise/admin/API/mnt/AcctStatusTT/MACAddress/{mac}/{seconds}&lt;BR /&gt;https://ise/admin/API/mnt/CoA/Reauth/{psn}/{mac}/{reauthtype}/{nas-ip}/{dst-ip}&lt;BR /&gt;https://ise/admin/API/mnt/CoA/Disconnect/{psn}/{mac}/&amp;lt;disconnecttype&amp;gt;/{nas-ip}/{dst-ip}&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; What kind of authorization rule is required to make it work?&lt;/P&gt;
&lt;P&gt;Have you looked at the ISE &lt;STRONG&gt;Default&lt;/STRONG&gt; Policy Set and the &lt;SPAN class="edited-span" contenteditable="true" data-id="policy-name-text-box"&gt;&lt;STRONG&gt;Wireless Black List&lt;/STRONG&gt;&lt;/SPAN&gt; authorization rule in ISE? Like that but you do not need to limit it to Wireless Access.&amp;nbsp; See &lt;A class="" href="https://community.cisco.com/t5/security-documents/ise-authentication-and-authorization-policy-reference/ta-p/3850472#toc-hId--2106958069" rel="nofollow noopener noreferrer" target="_blank"&gt;Static Endpoint Group(s)&lt;/A&gt; in &lt;LI-MESSAGE title="ISE Authentication and Authorization Policy Reference" uid="3850472" url="https://community.cisco.com/t5/security-documents/ise-authentication-and-authorization-policy-reference/m-p/3850472#U3850472"&gt;&lt;/LI-MESSAGE&gt; .&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse; font-size: .8em;" border="1" cellspacing="0" cellpadding="1"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Status&lt;/TH&gt;
&lt;TH&gt;Rule Name&lt;/TH&gt;
&lt;TH&gt;Conditions&lt;/TH&gt;
&lt;TH&gt;Profiles&lt;/TH&gt;
&lt;TH&gt;Security Groups&lt;/TH&gt;
&lt;TH&gt;Hits&lt;/TH&gt;
&lt;TH&gt;Actions&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center;"&gt;&lt;SPAN&gt;✔&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;Wireless Block List Default&lt;/TD&gt;
&lt;TD&gt;
&lt;TABLE style="border-style: hidden; margin: 0.2em;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;AND&lt;/TD&gt;
&lt;TD&gt;Wireless_Access&lt;BR /&gt;IdentityGroup-Name EQUALS Endpoint Identity Groups:Blocklist&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;TD&gt;Block_Wireless_Access&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Select from list&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="text-align: right;"&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="font-size: 1.5em; text-align: center;"&gt;⚙&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 08:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4586248#M573885</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-05T08:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to block a endpoint PC in Cisco ISE system?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4658481#M576372</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;check out the following tool which uses ISE API for MAC address management:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xtendise.com/" target="_blank"&gt;https://www.xtendise.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Jakub&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 11:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4658481#M576372</guid>
      <dc:creator>jakub.kacer</dc:creator>
      <dc:date>2022-07-27T11:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: From ISE identity management,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4813177#M581112</link>
      <description>&lt;P&gt;This is a very similar issue we have... an android device lost with user AD credentials in it attempting every minute to authenticate and causing the AD user account locked out. I added the mac address to a deny rule at the top in the authentication policy... but still issue occurred.... and was able to confirm this in the Operations -&amp;gt; Live Logs when filtering the mac address.... so i opened a TAC case and this is what they told me: "&lt;BR /&gt;"ISE is not able to block by MAC address without affecting the user because the device is using user authentication as its method, so when it tries to log in and fails (because of the policy to deny that MAC address) then blocks the user too, affecting the customer's real user. From ISE there is no way to block a MAC address before starting the process of authenticating, thats why the customer needs to get the MAC address to be blocked from the network access device (WLC).&lt;BR /&gt;Since the issue is that the endpoint has set as authentication method user authentication, and we dont have access to that endpoint, we wont be able to block the MAC address without affecting the user."&lt;/P&gt;&lt;P&gt;Is this legit??&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 21:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/m-p/4813177#M581112</guid>
      <dc:creator>asancheztellez</dc:creator>
      <dc:date>2023-04-12T21:05:55Z</dc:date>
    </item>
  </channel>
</rss>

