<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE - purge inactive endpoints in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615305#M574914</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any recommendation/best practice how to purge inactive endpoints from the database, in order to keep it clean and tidy, let's say, anything inactive for more then 100 days?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am running Cisco ISE 3.1 with Essential licensing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 10:29:37 GMT</pubDate>
    <dc:creator>milos_p</dc:creator>
    <dc:date>2022-05-23T10:29:37Z</dc:date>
    <item>
      <title>Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615305#M574914</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any recommendation/best practice how to purge inactive endpoints from the database, in order to keep it clean and tidy, let's say, anything inactive for more then 100 days?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am running Cisco ISE 3.1 with Essential licensing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 10:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615305#M574914</guid>
      <dc:creator>milos_p</dc:creator>
      <dc:date>2022-05-23T10:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615315#M574915</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_maintain_monitor.html#concept_0776B37A2C3542189950F5DFB1961FA2" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_maintain_monitor.html#concept_0776B37A2C3542189950F5DFB1961FA2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 10:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615315#M574915</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-05-23T10:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615322#M574916</link>
      <description>&lt;P&gt;Hi marc1000,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reply, just referring to the manual is not very helpful in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to see some real world examples for this, if someone is using any purge policy effectively in their deployment for purging inactive endpoints.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 10:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615322#M574916</guid>
      <dc:creator>milos_p</dc:creator>
      <dc:date>2022-05-23T10:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615571#M574918</link>
      <description>&lt;P&gt;It may be somewhat different between environments and how the groups are effectively used, how they are initially populated (dynamic vs static), and how quickly they grow.&lt;/P&gt;
&lt;P&gt;For example I've frequently seen deployments where the purge policy for guest endpoints is set to purge after 30 days (sometimes less).&lt;/P&gt;
&lt;P&gt;I know of an environment where group that's primarily used to identify devices being staged, and the purge policy on that group is only a few days. (Since effectively the endpoint should have been moved into another group post staging anyway.)&lt;/P&gt;
&lt;P&gt;60/90/120 inactive-days is what I frequently run into for different groups/use cases, but I also see an even longer time and/or combination with "never purge" for certain groups.&lt;/P&gt;
&lt;P&gt;It really is an "it depends".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 14:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615571#M574918</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2022-05-23T14:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615870#M574925</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1243243"&gt;@milos_p&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I prefer to use a combination of &lt;STRONG&gt;Conditions&lt;/STRONG&gt; in a &lt;STRONG&gt;Purge&lt;/STRONG&gt; rule, for examples:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;NotRegistered-Inactivity&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;(EndpointPurge.DeviceRegistrationStatus Equals NotRegistered) AND (EndpointPurge.InactiveDays GreaterThan &lt;U&gt;30&lt;/U&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I also use the ElapsedDays in some cases, for example:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Portal-Test&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;(Portal-Test) AND (EndpointPurge.ElapsedDays GreaterThan &lt;U&gt;1&lt;/U&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. at &lt;STRONG&gt;Context Visibility &amp;gt; Endpoints &amp;gt; Authentications&lt;/STRONG&gt; you are able to check the &lt;STRONG&gt;Dashboard - Inactive Endpoints&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. at &lt;STRONG&gt;Operations &amp;gt; Report &amp;gt; Reports &amp;gt; Audit &amp;gt; Endpoints Purge Activities&lt;/STRONG&gt;, you are able to check your &lt;STRONG&gt;Purge&lt;/STRONG&gt; rules.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 02:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615870#M574925</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-24T02:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615971#M574929</link>
      <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is super useful, especially report for &lt;STRONG&gt;Endpoint Purge Activities&lt;/STRONG&gt;, thanks a lot!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know some easy way to display all endpoints with Inactive days larger then X (let's say, I want to see all endpoints with inactive days more than 30 etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found a way to export all endpoints to CSV and find it from there, but a view/report from ISE GUI would be more useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 07:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4615971#M574929</guid>
      <dc:creator>milos_p</dc:creator>
      <dc:date>2022-05-24T07:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616474#M574933</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1243243"&gt;@milos_p&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;at &lt;STRONG&gt;Context Visibility &amp;gt; Endpoints &amp;gt; Authentication &amp;gt; Inactive Endpoints&lt;/STRONG&gt; dashboard, you are able to see and &lt;U&gt;select&lt;/U&gt; (like a &lt;U&gt;filter&lt;/U&gt;) the &lt;STRONG&gt;Inactive Endpoints&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="InactiveEndpoints.png" style="width: 769px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151854iC2F631BF71AABAD6/image-dimensions/769x390?v=v2" width="769" height="390" role="button" title="InactiveEndpoints.png" alt="InactiveEndpoints.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;After selecting, the list of &lt;STRONG&gt;Inactive Endpoints&lt;/STRONG&gt; (&lt;STRONG&gt;23723&lt;/STRONG&gt; in the example above) will be listed bellow (this is a way "&lt;EM&gt;to see all endpoints with inactive days more than&lt;/EM&gt;").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616474#M574933</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-24T13:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616492#M574935</link>
      <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still not sure if that "INACTIVE ENDPOINTS" chart will present all inactive endpoints, or just for certain amount of time, as it looks like chart is divided in 30 columns, so I guess it will show for last 30 days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, clicking on the chart on certain date will put in the filter "Inactive since X days" and show endpoints only for that date, not also before or after, I tested it.&lt;/P&gt;&lt;P&gt;You can try to click on your chart on a bar before or after the one with 23723 endpoints, and see if it will bring you 23723+X or just endpoints from that day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me, it shows only for the day that I clicked on the chart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616492#M574935</guid>
      <dc:creator>milos_p</dc:creator>
      <dc:date>2022-05-24T13:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616836#M574942</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1243243"&gt;@milos_p&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, your understanding is correct.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;When you click on the column the filter is applied to all &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; that are inactive for &lt;U&gt;exactly&lt;/U&gt; &lt;STRONG&gt;X&lt;/STRONG&gt; days:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="InactiveEndpoints - 01.png" style="width: 832px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151914i520F2F1FDA68BB40/image-dimensions/832x231?v=v2" width="832" height="231" role="button" title="InactiveEndpoints - 01.png" alt="InactiveEndpoints - 01.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 21:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616836#M574942</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-24T21:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616838#M574943</link>
      <description>&lt;P&gt;Hi Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great, so I understood it good, it's exactly for X days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a trick so I can see endpoints inactive for more than X days?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 22:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616838#M574943</guid>
      <dc:creator>milos_p</dc:creator>
      <dc:date>2022-05-24T22:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616912#M574946</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1243243"&gt;@milos_p&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;sorry, not that I know.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 02:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/4616912#M574946</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-25T02:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/5244057#M594033</link>
      <description>&lt;P&gt;Hey Marcelo!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something similar for inactive Network Devices? I have hundreds of network devices that have been retired and not cleaned up. Is there a purge option for something like that?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/5244057#M594033</guid>
      <dc:creator>JasonPawlowski6638</dc:creator>
      <dc:date>2025-01-06T19:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - purge inactive endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/5244074#M594035</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1058237"&gt;@JasonPawlowski6638&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;the &lt;STRONG&gt;Endpoint Purge&lt;/STRONG&gt; (at &lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Settings&lt;/STRONG&gt;) is for &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; only !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At &lt;STRONG&gt;Administration &amp;gt; Network Resources &amp;gt; Network Devices&lt;/STRONG&gt; &amp;gt; you can select the&amp;nbsp;&lt;STRONG&gt;Network Devices&lt;/STRONG&gt; and choose &lt;STRONG&gt;Delete &amp;gt; Delete Selected&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;To check the &lt;STRONG&gt;Authentications&lt;/STRONG&gt; of a &lt;STRONG&gt;Network Device&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="lia-align-justify"&gt;At &lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Authentication Summary&lt;/STRONG&gt; &amp;gt; check &lt;STRONG&gt;Authentications by Device Name&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;At&amp;nbsp;&lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Top N Authentications by Network Device&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-purge-inactive-endpoints/m-p/5244074#M594035</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-06T19:51:19Z</dc:date>
    </item>
  </channel>
</rss>

