<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Endpoint Group API in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605903#M574612</link>
    <description>&lt;P&gt;Exactly what i was looking for - thanks so much!&lt;/P&gt;</description>
    <pubDate>Fri, 06 May 2022 18:05:47 GMT</pubDate>
    <dc:creator>Wes Schochet</dc:creator>
    <dc:date>2022-05-06T18:05:47Z</dc:date>
    <item>
      <title>ISE Endpoint Group API</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605792#M574610</link>
      <description>&lt;P&gt;Hi-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for the ISE API call to get the endpoint IDs that are members of a particular endpoint identity group.&amp;nbsp; I have the group ID.&amp;nbsp; I can't find the right call....&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 14:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605792#M574610</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2022-05-06T14:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Endpoint Group API</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605866#M574611</link>
      <description>&lt;P&gt;Wes, the ISE APIs are documented @ &lt;A href="https://cs.co/ise-api" target="_blank"&gt;https://cs.co/ise-api&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;There is an area called &lt;STRONG&gt;Getting Started&lt;/STRONG&gt; with a page &lt;STRONG&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!read-a-resource" target="_self"&gt;Reading a Resource&lt;/A&gt;&lt;/STRONG&gt; that has a section &lt;STRONG&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!read-a-resource/adding-filter" target="_self"&gt;Adding Filters&lt;/A&gt; &lt;/STRONG&gt;which describes the Filter syntax which can be combined with &lt;STRONG&gt;&lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!read-a-resource/paging" target="_self"&gt;Paging&lt;/A&gt;&lt;/STRONG&gt; and &lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!read-a-resource/sorting" target="_self"&gt;Sorting&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;First, let us view the first page of Endpoint Identity Groups (up to 20 per page, by default)&amp;nbsp; including their IDs:&lt;/P&gt;
&lt;PRE&gt;curl \&lt;BR /&gt;--insecure \&lt;BR /&gt;--location \&lt;BR /&gt;--silent \&lt;BR /&gt;--header 'Accept: application/json' \&lt;BR /&gt;--user $ise_rest_username:$ise_rest_password \&lt;BR /&gt;--request GET &lt;STRONG&gt;https://$ise_hostname/ers/config/endpointgroup\?size\=100&lt;/STRONG&gt; \&lt;BR /&gt;| jq -C '.[].resources[] | [.id,.name,.description ] | join(" | ")'&lt;BR /&gt;"38a73670-8c00-11e6-996c-525400b48521 | Sony-Device | Identity Group for Profile: Sony-Device"&lt;BR /&gt;"1e2700a0-8c00-11e6-996c-525400b48521 | Cisco-Meraki-Device | Identity Group for Profile: Cisco-Meraki-Device"&lt;BR /&gt;"0a4a50f0-8c00-11e6-996c-525400b48521 | Apple-iDevice | Identity Group for Profile: Apple-iDevice"&lt;BR /&gt;"0cc7ad00-8c00-11e6-996c-525400b48521 | BlackBerry | Identity Group for Profile: BlackBerry"&lt;BR /&gt;"ffa36b00-8bff-11e6-996c-525400b48521 | Android | Identity Group for Profile: Android"&lt;BR /&gt;"0c4eac70-8c00-11e6-996c-525400b48521 | Axis-Device | Identity Group for Profile: Axis-Device"&lt;BR /&gt;"2b07d100-8c00-11e6-996c-525400b48521 | Juniper-Device | Identity Group for Profile: Juniper-Device"&lt;BR /&gt;"22c6c780-8c00-11e6-996c-525400b48521 | Epson-Device | Identity Group for Profile: Epson-Device"&lt;BR /&gt;"aa10ae00-8bff-11e6-996c-525400b48521 | Profiled | Profiled Identity Group"&lt;BR /&gt;"aa000c30-8bff-11e6-996c-525400b48521 | Blocked List | Blocked List Identity Group"&lt;BR /&gt;"aa178bd0-8bff-11e6-996c-525400b48521 | GuestEndpoints | Guest Endpoints Identity Group"&lt;BR /&gt;"3a1b38d0-8c00-11e6-996c-525400b48521 | Synology-Device | Identity Group for Profile: Synology-Device"&lt;BR /&gt;"a4cd21c0-fd75-11eb-b43c-ba8c06185168 | OS_X_BigSur-Workstation | Identity Group for Profile: OS_X_BigSur-Workstation"&lt;BR /&gt;"3b113190-8c00-11e6-996c-525400b48521 | Vizio-Device | Identity Group for Profile: Vizio-Device"&lt;BR /&gt;"3a88eec0-8c00-11e6-996c-525400b48521 | Trendnet-Device | Identity Group for Profile: Trendnet-Device"&lt;BR /&gt;"aa13bb40-8bff-11e6-996c-525400b48521 | RegisteredDevices | Asset Registered Endpoints Identity Group"&lt;BR /&gt;"4ea2a450-5c7a-11ec-a6b9-ce11946aeeed | Windows11-Workstation | Identity Group for Profile: Windows11-Workstation"&lt;BR /&gt;&lt;STRONG&gt;"14f5cac0-8c00-11e6-996c-525400b48521 | Cisco-IP-Phone | Identity Group for Profile: Cisco-IP-Phone"&lt;/STRONG&gt;&lt;BR /&gt;"aa0e8b20-8bff-11e6-996c-525400b48521 | Unknown | Unknown Identity Group"&lt;BR /&gt;"3b76f840-8c00-11e6-996c-525400b48521 | Workstation | Identity Group for Profile: Workstation"&lt;/PRE&gt;
&lt;P&gt;Now let's say we want the &lt;FONT face="courier new,courier"&gt;Cisco-IP-Phone&lt;/FONT&gt; endpoints with group ID &lt;FONT face="courier new,courier"&gt;14f5cac0-8c00-11e6-996c-525400b48521&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;If you look at the structure of an endpoint object (this one is a printer) the attribute for the Endpoint Identity Group is &lt;FONT face="courier new,courier"&gt;groupID&lt;/FONT&gt;:&lt;/P&gt;
&lt;PRE&gt;curl \&lt;BR /&gt;--insecure \&lt;BR /&gt;--location \&lt;BR /&gt;--silent \&lt;BR /&gt;--header 'Accept: application/json' \&lt;BR /&gt;--user $ise_rest_username:$ise_rest_password \&lt;BR /&gt;--request GET &lt;STRONG&gt;https://$ise_hostname/ers/config/endpoint/0e436440-cd53-11ec-bf2c-8220985ab925&lt;/STRONG&gt;&lt;BR /&gt;{&lt;BR /&gt;"ERSEndPoint" : {&lt;BR /&gt;"id" : "0e436440-cd53-11ec-bf2c-8220985ab925",&lt;BR /&gt;"name" : "00:00:AA:C0:93:18",&lt;BR /&gt;"description" : "Epson Printer",&lt;BR /&gt;"mac" : "00:00:AA:C0:93:18",&lt;BR /&gt;"profileId" : "44031480-8c00-11e6-996c-525400b48521",&lt;BR /&gt;"staticProfileAssignment" : false,&lt;BR /&gt;"staticProfileAssignmentDefined" : true,&lt;BR /&gt;&lt;STRONG&gt;"groupId" : "22c6c780-8c00-11e6-996c-525400b48521",&lt;/STRONG&gt;&lt;BR /&gt;"staticGroupAssignment" : true,&lt;BR /&gt;"staticGroupAssignmentDefined" : true,&lt;BR /&gt;"portalUser" : "",&lt;BR /&gt;"identityStore" : "",&lt;BR /&gt;"identityStoreId" : "",&lt;BR /&gt;"link" : {&lt;BR /&gt;"rel" : "self",&lt;BR /&gt;"href" : "https://198.18.133.27/ers/config/endpoint/0e436440-cd53-11ec-bf2c-8220985ab925",&lt;BR /&gt;"type" : "application/json"&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/PRE&gt;
&lt;P&gt;We can run a query against the endpoints using the &lt;FONT face="courier new,courier"&gt;groupID&lt;/FONT&gt; attribute matching the Endpoint Group ID for our Cisco-IP-Phones :&lt;/P&gt;
&lt;PRE&gt;curl \&lt;BR /&gt;--insecure \&lt;BR /&gt;--location \&lt;BR /&gt;--silent \&lt;BR /&gt;--header 'Accept: application/json' \&lt;BR /&gt;--user $ise_rest_username:$ise_rest_password \&lt;BR /&gt;--request GET &lt;STRONG&gt;https://$ise_hostname/ers/config/endpoint\?\&amp;amp;filter\=groupId.EQ.14f5cac0-8c00-11e6-996c-525400b48521&lt;/STRONG&gt; \&lt;BR /&gt;| jq -C '.[].resources[] | [.id,.name,.description ] | join(" | ")'&lt;BR /&gt;"0b36e790-cd53-11ec-bf2c-8220985ab925 | 00:11:BB:EF:EE:66 | IP Phone"&lt;BR /&gt;"0bdc7660-cd53-11ec-bf2c-8220985ab925 | 00:11:BB:5F:C4:28 | IP Phone"&lt;BR /&gt;"0c811ad0-cd53-11ec-bf2c-8220985ab925 | 00:11:BB:9E:57:BC | IP Phone"&lt;/PRE&gt;
&lt;P&gt;8-)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 16:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605866#M574611</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-05-06T16:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Endpoint Group API</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605903#M574612</link>
      <description>&lt;P&gt;Exactly what i was looking for - thanks so much!&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 18:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4605903#M574612</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2022-05-06T18:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Endpoint Group API</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4817090#M581254</link>
      <description>&lt;P&gt;Seems in ISE2.7 this do not work because:&lt;/P&gt;
&lt;PRE&gt;GET &lt;STRONG&gt;&lt;A href="https://$ise_hostname/ers/config/endpoint" target="_blank"&gt;https://$ise_hostname/ers/config/endpoint&lt;/A&gt;&lt;BR /&gt;does not include the groupId in the endpoint-dict ??&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;it only shows:&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"id"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"1d818dc0-5ff7-11e7-a32e-005056b315ee"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"name"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"00:00:00:00:00:01"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"link"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;{&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"rel"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"self"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"href"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"https://&amp;lt;ISE-IP&amp;gt;:9060/ers/config/endpoint/1d818dc0-5ff7-11e7-a32e-005056b315ee"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"type"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"application/json"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 16:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-endpoint-group-api/m-p/4817090#M581254</guid>
      <dc:creator>HUBERT RESCH</dc:creator>
      <dc:date>2023-04-18T16:36:31Z</dc:date>
    </item>
  </channel>
</rss>

