<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pxGrid and pxGrid Direct connector - CoA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145751#M590683</link>
    <description>&lt;P&gt;With pxGrid, the connection to the pxGrid pub/sub bus is initiated by the Subscriber, but all subsequent communications are issued by the Publisher (ISE). Updates published to the pxGrid pub/sub bus will be received by the Subscribers. The topics involved, depend on the Subscriber and what capabilities it supports. There is no CoA triggered by pxGrid itself by either the Publisher or Subscriber. A CoA is typically triggered by the ISE Profiler in the case that a significant profile change, an integrated system using the Adaptive Network Control (ANC) API (as is the case for Secure Network Analytics), or using the ISE MnT API.&lt;BR /&gt;See&amp;nbsp;&lt;A id="video-title" class="yt-simple-endpoint style-scope ytd-video-renderer" title="Introduction to the Cisco Platform Exchange Grid pxGrid in ISE" href="https://www.youtube.com/watch?v=_aO6oZrYCPE" aria-label="Introduction to the Cisco Platform Exchange Grid pxGrid in ISE by Cisco ISE - Identity Services Engine 6,081 views 1 year ago 55 minutes" target="_blank"&gt;Introduction to the Cisco Platform Exchange Grid pxGrid in ISE&lt;/A&gt;&amp;nbsp;for more information on pxGrid.&lt;/P&gt;
&lt;P&gt;For pxGrid Direct, AFAIK, there is also no CoA triggered directly by this feature. If an asset attribute value changes, it will only be evaluated if a re-authentication or new auth session occurs, or if a CoA is initiated manually or via API.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jul 2024 23:48:00 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2024-07-16T23:48:00Z</dc:date>
    <item>
      <title>pxGrid and pxGrid Direct connector - CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145155#M590648</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;question regarding CoA in pxGrid.&lt;/P&gt;&lt;P&gt;We will implement pxGrid with third-party integration (ARMIS / SentinalONE).&lt;/P&gt;&lt;P&gt;we have a couple of options, ERS / pxGrid / pxGrid direct connector (ISE 3.3).&lt;/P&gt;&lt;P&gt;in two if them (pxGrid / pxGrid Direct Connector), how does CoA occur?&lt;/P&gt;&lt;P&gt;if you can share some knowledgebase I will be thankful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 19:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145155#M590648</guid>
      <dc:creator>oron.yaniv</dc:creator>
      <dc:date>2024-07-15T19:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid and pxGrid Direct connector - CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145350#M590658</link>
      <description>&lt;P&gt;Irrespective of whether or not pxGrid is involved, if a CoA is required to trigger re-auth of an endpoint, the CoA is sent from the PSN that owns the endpoint. This means the IP addresses of the PSNs must be configured on NAS devices with the correct RADIUS shared secret, and UDP/1700 must be allowed from PSN -&amp;gt; NAS devices.&lt;/P&gt;
&lt;P&gt;Not sure there are any other subtleties involved. I don't have experience with pxGrid triggering the CoA, but since it's all done via API I don't believe there is any difference in how CoA is implemented&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 06:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145350#M590658</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-16T06:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid and pxGrid Direct connector - CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145518#M590660</link>
      <description>&lt;P&gt;thanks for replying and sharing the info.&lt;/P&gt;&lt;P&gt;the question is more on the pxgrid side before the ISE mechanism even issues the CoA to NAD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the question is focused on the PUB/SUB mechanism, and how it occurred in pxGrid. in pxGrid the communication is initiated from the Subscriber. and I expect the CoA will be issued from the subscriber. i asked myself how its worked under the hood (which pxgrid topic was involved, which request initiates from the publisher, if any)&lt;/P&gt;&lt;P&gt;and second question, how it occur in pxGrid direct connect?&lt;BR /&gt;in pxGrid Direct connect the communication changed, ISE Pulling information from external Data source (in JSON format), so in that point, after data populate or change over time - how does CoA occur?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 12:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145518#M590660</guid>
      <dc:creator>oron.yaniv</dc:creator>
      <dc:date>2024-07-16T12:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid and pxGrid Direct connector - CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145751#M590683</link>
      <description>&lt;P&gt;With pxGrid, the connection to the pxGrid pub/sub bus is initiated by the Subscriber, but all subsequent communications are issued by the Publisher (ISE). Updates published to the pxGrid pub/sub bus will be received by the Subscribers. The topics involved, depend on the Subscriber and what capabilities it supports. There is no CoA triggered by pxGrid itself by either the Publisher or Subscriber. A CoA is typically triggered by the ISE Profiler in the case that a significant profile change, an integrated system using the Adaptive Network Control (ANC) API (as is the case for Secure Network Analytics), or using the ISE MnT API.&lt;BR /&gt;See&amp;nbsp;&lt;A id="video-title" class="yt-simple-endpoint style-scope ytd-video-renderer" title="Introduction to the Cisco Platform Exchange Grid pxGrid in ISE" href="https://www.youtube.com/watch?v=_aO6oZrYCPE" aria-label="Introduction to the Cisco Platform Exchange Grid pxGrid in ISE by Cisco ISE - Identity Services Engine 6,081 views 1 year ago 55 minutes" target="_blank"&gt;Introduction to the Cisco Platform Exchange Grid pxGrid in ISE&lt;/A&gt;&amp;nbsp;for more information on pxGrid.&lt;/P&gt;
&lt;P&gt;For pxGrid Direct, AFAIK, there is also no CoA triggered directly by this feature. If an asset attribute value changes, it will only be evaluated if a re-authentication or new auth session occurs, or if a CoA is initiated manually or via API.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 23:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145751#M590683</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-07-16T23:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: pxGrid and pxGrid Direct connector - CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145763#M590684</link>
      <description>&lt;P&gt;pxGrid (pub/sub) is different than pxGrid Direct (REST-based data dictionary synchronization).&lt;/P&gt;
&lt;P&gt;pxGrid achieves COA via &lt;A href="https://github.com/cisco-pxgrid/pxgrid-rest-ws/wiki/ANC-configuration" target="_self"&gt;Adaptive Network Control (ANC)&lt;/A&gt; APIs. This is how all of the integrated security solutions do it. You may read to read more about this from &lt;A href="https://cs.co/ise-berg#pxgrid" target="_blank"&gt;https://cs.co/ise-berg#pxgrid&lt;/A&gt; and &lt;A href="https://cs.co/ise-berg#anc" target="_blank"&gt;https://cs.co/ise-berg#anc&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 00:23:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxgrid-and-pxgrid-direct-connector-coa/m-p/5145763#M590684</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-07-17T00:23:27Z</dc:date>
    </item>
  </channel>
</rss>

