<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nested Endpoint Identity Groups - What for? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295684#M596602</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;that's a great workaround - your naming conventions allows me to create the hierarchy in "Administration / Identity Management / Endpoint Identity Groups" screen to collapse the Groups under their parents. I like that! Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2025 05:36:58 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-06-02T05:36:58Z</dc:date>
    <item>
      <title>Nested Endpoint Identity Groups - What for?</title>
      <link>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295676#M596600</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I like the idea of creating EIG (Endpoint Identity Groups) in a hierarchical fashion, but I have run into a limitation - wondering if there is a solution for this.&lt;/P&gt;
&lt;P&gt;If you create an EIG Hierarchy as follows:&lt;/P&gt;
&lt;PRE&gt;Parent 1
Parent 2&lt;/PRE&gt;
&lt;P&gt;and under each Parent, create a Child 1 Endpoint Identity Group, so that the result looks like this:&lt;/P&gt;
&lt;PRE&gt;Parent 1
&amp;nbsp; Child 1
Parent 2
  Child 1&lt;/PRE&gt;
&lt;P&gt;then you can create RADIUS Policy Set rules that refer to each Parent:Child relationship (where the semicolon is the delimiter) as&lt;/P&gt;
&lt;P&gt;"Parent 1:Child 1"&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;"Parent 2:Child 1"&lt;/P&gt;
&lt;P&gt;However, in Context Visibility, you cannot tell who the parent is when an endpoint is assigned as "Child 1" of either parent - that level of granularity is not available. In Context Visibility, you can statically set an EIG, but in the drop-down list, the options appear as&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Child 1
Child 1&lt;/PRE&gt;
&lt;P&gt;No context about the parent.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Context Visibility Browser, you don't see the Parent details either, and even worse, in the CSV import, there is no way to be specific about the exact Parent:Child relationship- you can only specify an EIG name - who knows where the endpoint will be assigned to...&lt;/P&gt;
&lt;P&gt;So is it a bug, or just lacking feature support in ISE ?&amp;nbsp; Why allow hierarchical nesting of groups, when the implications of using such a feature makes it very hard (or pointless) in practice?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 04:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295676#M596600</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-06-02T04:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Endpoint Identity Groups - What for?</title>
      <link>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295683#M596601</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I totally agree !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;For me is&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;"just lacking feature support in ISE" ... as a workaround, what I do is something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;Parent 1
&amp;nbsp; P1-Child 1
Parent 2
  P2-Child 1&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Best regards&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 05:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295683#M596601</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-06-02T05:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Endpoint Identity Groups - What for?</title>
      <link>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295684#M596602</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;that's a great workaround - your naming conventions allows me to create the hierarchy in "Administration / Identity Management / Endpoint Identity Groups" screen to collapse the Groups under their parents. I like that! Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 05:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nested-endpoint-identity-groups-what-for/m-p/5295684#M596602</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-06-02T05:36:58Z</dc:date>
    </item>
  </channel>
</rss>

