<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot do Endpoint purge on ISE 3.1 P6 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5161551#M591236</link>
    <description>&lt;P&gt;The purge rules don't have a limit on how many endpoints they will process. The purge rule will be processed against every endpoint, and if the rule is True, then the endpoint is deleted. That's why you must think carefully about what you're deleting - I always ensure that I never delete any endpoint that I have statically assigned to an endpoint (other than, say, ones for PXE Boot). There is a section above the purge rule that says "Never Purge" and I add those rules there - that protects them.&lt;/P&gt;
&lt;P&gt;You've reminded me to look at my own rules now to see if they are working well - I reckon in most customer ISE deployments there are more stale/dead endpoints than necessary and could use a bit of housekeeping.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 20:52:17 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-08-15T20:52:17Z</dc:date>
    <item>
      <title>Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5120186#M589719</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;There are lots of total endpoints amount on ISE dashboard.&lt;/P&gt;&lt;P&gt;As per reviews around 70% of endpoint are unknown.&lt;/P&gt;&lt;P&gt;We try to perform purge but cannot reduce above unknown devices.&lt;/P&gt;&lt;P&gt;Is it spice CPU issue regarding on ISE 3.1 P6?&lt;/P&gt;&lt;P&gt;In case we&amp;nbsp; still cannot purge, does ISE become slow performance or leak another unavailable options/services?&lt;/P&gt;&lt;P&gt;Kindly share / advise how we can reduce the unknown device by do endpoint purge or else.&lt;/P&gt;&lt;P&gt;Thanks for your update and supporting.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 04:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5120186#M589719</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-05-30T04:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5121491#M589741</link>
      <description>&lt;P&gt;There is no harm in leaving unknown endpoints lying around in ISE. it does not make ISE slower.&amp;nbsp; If you were to reach 2 million or more endpoints though, you would be reaching the maximum tested limit by Cisco. Don't let it get to that stage!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can delete endpoints in Context Visibility - up to 500 at a time. Filter on the ones you want to delete and select the maximum (e.g. 500) from the Rows/Page drop-down. Then tick the very first checkbox that selects all 500. Click Delete. Deletion can take a few minutes. Be patient - the GUI will return to normal.&lt;/P&gt;
&lt;P&gt;But if you have thousands to delete, then a purge job would be the way to go.&lt;/P&gt;
&lt;P&gt;Purge Rule&lt;/P&gt;
&lt;P&gt;If Unknown AND ENDPOINTPURGE ElapsedDays GREATERTHAN 0&lt;/P&gt;
&lt;P&gt;The only trick with that purge rule is that you cannot use the Endpoint Identity Group "Unknown" in another purge rule - ISE will complain.&lt;/P&gt;
&lt;P&gt;Be very certain that you are OK deleting endpoints that land in the Unknown Endpoint Identity Group.&amp;nbsp; &amp;nbsp;If you are running a Gust Wi-Fi solution in ISE, then you are probably collecting many Unknowns, because of MAC address privacy settings in devices. These MAC addresses will not have a MAC OUI vendor prefix and therefore are genuine unknowns.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 23:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5121491#M589741</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-30T23:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154460#M591015</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Endpoint Purge&lt;/P&gt;&lt;P&gt;we need to purge all UNKNOWN device with below condition.&lt;/P&gt;&lt;P&gt;- Unknown AND ENDPOINTPURGR InactiveDays GREATERTHAN 30&lt;/P&gt;&lt;P&gt;- ENDPOINTPURGE InactiveDays GRATHERTHAN 90&lt;/P&gt;&lt;P&gt;Which condtion we can perform purge?&lt;/P&gt;&lt;P&gt;To ensure no impact to other Active Endpoint PCs and MAB profiling.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 09:53:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154460#M591015</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-08-01T09:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154730#M591029</link>
      <description>&lt;P&gt;If I understand correctly, you want to purge inactive &amp;lt; 90 days endpoints that are in ANY Endpoint Identity Group - this is not possible because ISE expects you to select from the list of available Endpoint Identity Groups (or Profiling policies) - maybe select the Profiled Endpoints Identity Group, since you already took care of the Unknown ones.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 20:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154730#M591029</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-08-01T20:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154771#M591031</link>
      <description>&lt;P&gt;Yes, you are right.&lt;/P&gt;&lt;P&gt;Is it possible extend scope to this purge condition "&lt;SPAN&gt;&amp;nbsp;Unknown AND ENDPOINTPURGR InactiveDays GREATERTHAN 30&lt;/SPAN&gt;"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 01:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5154771#M591031</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-08-02T01:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5158084#M591158</link>
      <description>&lt;P&gt;what do you mean by "extend scope" ?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 00:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5158084#M591158</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-08-09T00:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5159921#M591194</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Is there any way to delete Older ""Disconnected"" endpoints&amp;nbsp; ? we can delete endpoints in Context Visibility - up to 500 at a time but manually it is an time consuming as we have multiple older disconnected endpoints.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rakesh&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Aug 2024 04:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5159921#M591194</guid>
      <dc:creator>rakeshdalvi</dc:creator>
      <dc:date>2024-08-13T04:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot do Endpoint purge on ISE 3.1 P6</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5161551#M591236</link>
      <description>&lt;P&gt;The purge rules don't have a limit on how many endpoints they will process. The purge rule will be processed against every endpoint, and if the rule is True, then the endpoint is deleted. That's why you must think carefully about what you're deleting - I always ensure that I never delete any endpoint that I have statically assigned to an endpoint (other than, say, ones for PXE Boot). There is a section above the purge rule that says "Never Purge" and I add those rules there - that protects them.&lt;/P&gt;
&lt;P&gt;You've reminded me to look at my own rules now to see if they are working well - I reckon in most customer ISE deployments there are more stale/dead endpoints than necessary and could use a bit of housekeeping.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 20:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-do-endpoint-purge-on-ise-3-1-p6/m-p/5161551#M591236</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-08-15T20:52:17Z</dc:date>
    </item>
  </channel>
</rss>

