<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add multiple Network devices in same group in Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5206152#M592346</link>
    <description>&lt;P&gt;Whilst it's handy to use subnet ranges in the ISE Network Devices definition, my main concern with it is that when you look at Live Logs, you won't see exactly which device sent the request - you will see the name you've assigned to the entire subnet. You have to click on each Live Log to reveal the NAS IP Address details. If that doesn't bother you, then the next concern would be "security" - however, the attacker might add themselves into the LAN and talk to ISE if it knew the RADIUS shared secret. I don't know if security is the main concern - it's just tidier to have /32's in ISE, and it also allows for easier auditing - e.g. in a /24 subnet, you will never know how many RADIUS clients you have - on the other hand, if you specify each one as a /32, then you have a clear and documented audit of that subnet's devices.&lt;/P&gt;
&lt;P&gt;I would assume that for large customers that e.g. have a subnet just for Meraki WAPs, they might rather use subnet notation in ISE, rather than adding thousands of WAPs into ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Horses for courses.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2024 22:56:14 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-10-09T22:56:14Z</dc:date>
    <item>
      <title>Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205664#M592313</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;BR /&gt;First post ever so I might be doing this wrong....&lt;BR /&gt;&lt;BR /&gt;I am to add a new /24 network in an existing Network Device list.&lt;BR /&gt;This due to the existing IP range is for a temporary setup still running in a temporary location and I am now setting up the permanent site in another IP range in same "group" as i want to keep the name.&lt;/P&gt;&lt;P&gt;I just want to know 2 things.&lt;/P&gt;&lt;P&gt;1. Is this OK, i do not "disturb" the temporary setup as that site is in full "production"&lt;/P&gt;&lt;P&gt;2. Is there any rule/to think about how i put the order of the networks (like an access-list)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Draken_1-1728465204435.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/230911i23ACD8ABA0ACC026/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Draken_1-1728465204435.png" alt="Draken_1-1728465204435.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 09:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205664#M592313</guid>
      <dc:creator>Draken</dc:creator>
      <dc:date>2024-10-09T09:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205670#M592314</link>
      <description>&lt;P&gt;Check if you get your answer from link below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.grandmetric.com/knowledge-base/design_and_configure/cisco-ise-3-0-nad/" target="_blank"&gt;https://www.grandmetric.com/knowledge-base/design_and_configure/cisco-ise-3-0-nad/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 09:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205670#M592314</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-09T09:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205679#M592315</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1517810"&gt;@Draken&lt;/a&gt; instead of modifying an existing NAD object, just create a new NAD with the new IP address range, define the shared secret and specify the correct location and Device Type group any other specific settings. The incoming request will match the NAD based on the source IP address.&lt;/P&gt;
&lt;P&gt;There is no ACL that I am aware of to order the network, it will depend on the incoming IP address received by ISE.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 09:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205679#M592315</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-09T09:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205811#M592325</link>
      <description>&lt;P&gt;We don't generally put entire networks in the network device list. We put the actual address of individual network devices.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205811#M592325</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-09T14:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205838#M592327</link>
      <description>&lt;P&gt;Thanks, I will read this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Draken&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205838#M592327</guid>
      <dc:creator>Draken</dc:creator>
      <dc:date>2024-10-09T14:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205839#M592328</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I thought that this would be the case but i wanted to keep my existing name.&lt;BR /&gt;But i do it the easy (and most correct) way and configure a new NAD.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;//Draken&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205839#M592328</guid>
      <dc:creator>Draken</dc:creator>
      <dc:date>2024-10-09T14:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205843#M592329</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Well the /24 is the range for my network equipment at that site won´t be anything else in there.&lt;/P&gt;&lt;P&gt;But maybe i should reconsider as best and secure practice?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5205843#M592329</guid>
      <dc:creator>Draken</dc:creator>
      <dc:date>2024-10-09T14:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5206152#M592346</link>
      <description>&lt;P&gt;Whilst it's handy to use subnet ranges in the ISE Network Devices definition, my main concern with it is that when you look at Live Logs, you won't see exactly which device sent the request - you will see the name you've assigned to the entire subnet. You have to click on each Live Log to reveal the NAS IP Address details. If that doesn't bother you, then the next concern would be "security" - however, the attacker might add themselves into the LAN and talk to ISE if it knew the RADIUS shared secret. I don't know if security is the main concern - it's just tidier to have /32's in ISE, and it also allows for easier auditing - e.g. in a /24 subnet, you will never know how many RADIUS clients you have - on the other hand, if you specify each one as a /32, then you have a clear and documented audit of that subnet's devices.&lt;/P&gt;
&lt;P&gt;I would assume that for large customers that e.g. have a subnet just for Meraki WAPs, they might rather use subnet notation in ISE, rather than adding thousands of WAPs into ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Horses for courses.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 22:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5206152#M592346</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-09T22:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Add multiple Network devices in same group in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5207020#M592392</link>
      <description>&lt;P&gt;Hi Arne.&lt;/P&gt;&lt;P&gt;Thanks for a good input, will take this to the team.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;//Michael&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 07:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/add-multiple-network-devices-in-same-group-in-cisco-ise/m-p/5207020#M592392</guid>
      <dc:creator>Draken</dc:creator>
      <dc:date>2024-10-11T07:48:04Z</dc:date>
    </item>
  </channel>
</rss>

