<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Configuration Tidy up tips and tricks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740534#M578860</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1444665"&gt;@SamSmith3&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;1st&lt;/STRONG&gt; at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Backup &amp;amp; Restore &amp;gt; Policy Export&lt;/STRONG&gt; &amp;gt; click the &lt;STRONG&gt;Export Now&lt;/STRONG&gt; (&lt;EM&gt;Encryption: Export without encryption&lt;/EM&gt; &amp;amp; &lt;EM&gt;Destination: Download file to local computer&lt;/EM&gt;) ... to download a &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt; file (you can also do this via &lt;STRONG&gt;Support Bundle&lt;/STRONG&gt; when you choose &lt;EM&gt;Include Policy Configuration&lt;/EM&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Policy Export.png" style="width: 884px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/171211iDBEAC7F4B7E38563/image-dimensions/884x610?v=v2" width="884" height="610" role="button" title="Policy Export.png" alt="Policy Export.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt; at &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; a. all &lt;STRONG&gt;&amp;lt;radiusPolicySet&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;name&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;Policy Set Name&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;rank&amp;gt; &lt;EM&gt;Position in the Policy Set&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/rank&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;allowedProtocols&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Allowed Protocol Name&amp;nbsp;&lt;/EM&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/allowedProtocols&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;status&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;ENABLED/DISABLED&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/status&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; b. all &lt;STRONG&gt;&amp;lt;authorRules&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;name&amp;gt; &lt;EM&gt;Rule Name&lt;/EM&gt; &amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;profiles&amp;gt; &lt;EM&gt;Authorization Profile Name&lt;/EM&gt; &amp;lt;/profiles&amp;gt;&lt;BR /&gt;&amp;lt;rank&amp;gt; &lt;EM&gt;Position in the Rule&lt;/EM&gt; &amp;lt;/rank&amp;gt;&lt;BR /&gt;&amp;lt;status&amp;gt; &lt;EM&gt;ENABLED/DISABLE&lt;/EM&gt; &amp;lt;/status&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; c. all &lt;STRONG&gt;&amp;lt;AznResults&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;Profile description="&lt;EM&gt;Authz Profile Description&lt;/EM&gt;" nadProfileName="&lt;EM&gt;NAD Name&lt;/EM&gt;" name="&lt;EM&gt;Name of the Authz Profile&lt;/EM&gt;"&amp;gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;option&lt;SPAN class="html-attribute"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-attribute-name"&gt;name&lt;/SPAN&gt;="&lt;SPAN class="html-attribute-value"&gt;Attributes Details&lt;/SPAN&gt;"&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;DACL = &lt;EM&gt;DACL Name&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/option&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;3rd.&lt;/STRONG&gt;&amp;nbsp;for clean up ... check (&lt;EM&gt;CRTL-F&lt;/EM&gt; the &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;) for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; a. a &lt;U&gt;&lt;EM&gt;name="Name of the Authz Profile"&lt;/EM&gt;&lt;/U&gt; inside the &lt;STRONG&gt;&amp;lt;AznResults&amp;gt;&lt;/STRONG&gt;, if there is ONLY one match, then you are able to remove this &lt;STRONG&gt;AuthZ Profile&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; b. to remove an unused &lt;STRONG&gt;dACL&lt;/STRONG&gt;, you must get the name of each &lt;STRONG&gt;dACL&lt;/STRONG&gt; (at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authorization &amp;gt; Downloadable ACLs&lt;/STRONG&gt;) and &lt;STRONG&gt;CTRL-F&lt;/STRONG&gt; the &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;, if there is NO match, then you are able to remove this &lt;STRONG&gt;dACL&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Hope this helps !!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Dec 2022 12:21:51 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2022-12-16T12:21:51Z</dc:date>
    <item>
      <title>ISE Configuration Tidy up tips and tricks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740487#M578858</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in the process of auditing and tidying up the configuration of our Cisco ISE 3.0 deployment. I would like to do the following as was hoping that there was an easier way to see the relationships between policy sets, Authz Policies, DACLs etc and find what is in use/not in use so I can have a clear out.&lt;/P&gt;&lt;P&gt;- Define the relationships between Policy sets | AuthZ Policies | Authz Profiles | DACLs and so forth&lt;/P&gt;&lt;P&gt;- Define and remove any unused Authz Profiles | DACLs and so forth&lt;/P&gt;&lt;P&gt;- An export of all policy sets and components into CSV of something easier to read rather than going through each one&lt;/P&gt;&lt;P&gt;-&amp;nbsp;An export of all Authz Profiles and components including DACLs into CSV of something easier to read rather than going through each one&lt;/P&gt;&lt;P&gt;- An Export of the portals we have and their components into CSV of something easier to read rather than going through each one&lt;/P&gt;&lt;P&gt;Any help is most appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sam&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 10:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740487#M578858</guid>
      <dc:creator>SamSmith3</dc:creator>
      <dc:date>2022-12-16T10:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Configuration Tidy up tips and tricks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740534#M578860</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1444665"&gt;@SamSmith3&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;1st&lt;/STRONG&gt; at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Backup &amp;amp; Restore &amp;gt; Policy Export&lt;/STRONG&gt; &amp;gt; click the &lt;STRONG&gt;Export Now&lt;/STRONG&gt; (&lt;EM&gt;Encryption: Export without encryption&lt;/EM&gt; &amp;amp; &lt;EM&gt;Destination: Download file to local computer&lt;/EM&gt;) ... to download a &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt; file (you can also do this via &lt;STRONG&gt;Support Bundle&lt;/STRONG&gt; when you choose &lt;EM&gt;Include Policy Configuration&lt;/EM&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Policy Export.png" style="width: 884px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/171211iDBEAC7F4B7E38563/image-dimensions/884x610?v=v2" width="884" height="610" role="button" title="Policy Export.png" alt="Policy Export.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt; at &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; a. all &lt;STRONG&gt;&amp;lt;radiusPolicySet&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;name&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;Policy Set Name&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;rank&amp;gt; &lt;EM&gt;Position in the Policy Set&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/rank&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;allowedProtocols&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Allowed Protocol Name&amp;nbsp;&lt;/EM&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/allowedProtocols&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;status&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;ENABLED/DISABLED&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/status&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; b. all &lt;STRONG&gt;&amp;lt;authorRules&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;name&amp;gt; &lt;EM&gt;Rule Name&lt;/EM&gt; &amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;profiles&amp;gt; &lt;EM&gt;Authorization Profile Name&lt;/EM&gt; &amp;lt;/profiles&amp;gt;&lt;BR /&gt;&amp;lt;rank&amp;gt; &lt;EM&gt;Position in the Rule&lt;/EM&gt; &amp;lt;/rank&amp;gt;&lt;BR /&gt;&amp;lt;status&amp;gt; &lt;EM&gt;ENABLED/DISABLE&lt;/EM&gt; &amp;lt;/status&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; c. all &lt;STRONG&gt;&amp;lt;AznResults&amp;gt;&lt;/STRONG&gt; have a:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;Profile description="&lt;EM&gt;Authz Profile Description&lt;/EM&gt;" nadProfileName="&lt;EM&gt;NAD Name&lt;/EM&gt;" name="&lt;EM&gt;Name of the Authz Profile&lt;/EM&gt;"&amp;gt;&lt;BR /&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;option&lt;SPAN class="html-attribute"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-attribute-name"&gt;name&lt;/SPAN&gt;="&lt;SPAN class="html-attribute-value"&gt;Attributes Details&lt;/SPAN&gt;"&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;DACL = &lt;EM&gt;DACL Name&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/option&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;3rd.&lt;/STRONG&gt;&amp;nbsp;for clean up ... check (&lt;EM&gt;CRTL-F&lt;/EM&gt; the &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;) for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; a. a &lt;U&gt;&lt;EM&gt;name="Name of the Authz Profile"&lt;/EM&gt;&lt;/U&gt; inside the &lt;STRONG&gt;&amp;lt;AznResults&amp;gt;&lt;/STRONG&gt;, if there is ONLY one match, then you are able to remove this &lt;STRONG&gt;AuthZ Profile&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; b. to remove an unused &lt;STRONG&gt;dACL&lt;/STRONG&gt;, you must get the name of each &lt;STRONG&gt;dACL&lt;/STRONG&gt; (at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authorization &amp;gt; Downloadable ACLs&lt;/STRONG&gt;) and &lt;STRONG&gt;CTRL-F&lt;/STRONG&gt; the &lt;STRONG&gt;PolicyConfig.xml&lt;/STRONG&gt;, if there is NO match, then you are able to remove this &lt;STRONG&gt;dACL&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Hope this helps !!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 12:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740534#M578860</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-12-16T12:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Configuration Tidy up tips and tricks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740535#M578861</link>
      <description>&lt;P&gt;That's great this really is helpful thank you so much!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 12:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-configuration-tidy-up-tips-and-tricks/m-p/4740535#M578861</guid>
      <dc:creator>SamSmith3</dc:creator>
      <dc:date>2022-12-16T12:21:17Z</dc:date>
    </item>
  </channel>
</rss>

