Skip to main content

Network Device

Location in GUI: Administration » Network Resources » Network Devices

Diagram

Classes

network_resources (ise)

NameTypeConstraintMandatoryDefault Value
network_devicesList[network_devices]No

network_devices (ise.network_resources)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[\w\d_\-\.]+$Yes
descriptionStringNo
ipsList[ips]No
profile_nameStringNoCisco
model_nameStringNo
software_versionStringNo
network_device_groupsListStringNo
authentication_network_protocolChoiceRADIUS, TACACS_PLUSNo
radiusClass[radius]No
tacacsClass[tacacs]No
snmpClass[snmp]No
trust_secClass[trust_sec]No

ips (ise.network_resources.network_devices)

NameTypeConstraintMandatoryDefault Value
ipStringYes
ip_excludeStringNo
maskIntegermin: 0, max: 128No32

radius (ise.network_resources.network_devices)

NameTypeConstraintMandatoryDefault Value
shared_secretStringNo
second_shared_secretStringNo
coa_portIntegermin: 1, max: 65535No1700
dtls_requiredBooleantrue, falseNofalse
dtls_dns_nameStringNo
enable_key_wrapBooleantrue, falseNofalse
encryption_keyStringNo
encryption_key_formatChoiceASCII, HEXADECIMALNoASCII
message_authenticator_code_keyStringNo

tacacs (ise.network_resources.network_devices)

NameTypeConstraintMandatoryDefault Value
connect_mode_optionsChoiceOFF, ON_LEGACY, ON_DRAFT_COMPLIANTNoOFF
shared_secretStringNo

snmp (ise.network_resources.network_devices)

NameTypeConstraintMandatoryDefault Value
link_trap_queryBooleantrue, falseNotrue
mac_trap_queryBooleantrue, falseNotrue
originating_policy_services_nodeStringNo
polling_intervalIntegermin: 600, max: 86400No28800
ro_communityStringNo
versionChoiceONE, TWO_C, THREENo

trust_sec (ise.network_resources.network_devices)

NameTypeConstraintMandatoryDefault Value
device_idStringNo
device_passwordStringNo
rest_api_usernameStringNo
rest_api_passwordStringNo
download_enviroment_data_every_x_secondsIntegermin: 0No86400
download_peer_authorization_policy_every_x_secondsIntegermin: 0No86400
re_authentication_every_x_secondsIntegermin: 0No86400
download_sgacl_lists_every_x_secondsIntegermin: 0No86400
other_sga_devices_to_trust_this_deviceBooleantrue, falseNotrue
send_configuration_to_deviceBooleantrue, falseNofalse
send_configuration_to_device_usingChoiceENABLE_USING_COA, ENABLE_USING_CLI, DISABLE_ALLNoDISABLE_ALL
coa_source_hostStringNo
include_when_deploying_sgt_updatesBooleantrue, falseNofalse
exec_mode_usernameStringNo
exec_mode_passwordStringNo
enable_mode_passwordStringNo

Examples

Simple example:

ise:
network_resources:
network_devices:
- name: Router1
ips:
- ip: 10.1.2.3
radius:
shared_secret: Cisco123

Full example:

ise:
network_resources:
network_devices:
- name: Switch1
description: My first switch
ips:
- ip: 10.1.2.3
network_device_groups:
- Is IPSEC Device
- All Device Types
- All Locations
profile_name: Cisco
model_name: C9300-24UX
software_version: "17.10.1"
authentication_network_protocol: RADIUS
radius:
shared_secret: Cisco123
second_shared_secret: Cisco1234
coa_port: 1701
dtls_required: true
dtls_dns_name: cisco.com
enable_key_wrap: true
encryption_key: Cisco123Cisco123
encryption_key_format: ASCII
message_authenticator_code_key: Cisco123Cisco1231234
tacacs:
connect_mode_options: ON_LEGACY
shared_secret: Cisco123
snmp:
link_trap_query: false
mac_trap_query: false
polling_interval: 10000
originating_policy_services_node: ise1
ro_community: Cisco123
version: TWO_C
trust_sec:
device_id: Dev1
device_password: Cisco123
rest_api_username: dev1
rest_api_password: Cisco123
download_enviroment_data_every_x_seconds: 10000
download_peer_authorization_policy_every_x_seconds: 10000
re_authentication_every_x_seconds: 10000
download_sgacl_lists_every_x_seconds: 10000
other_sga_devices_to_trust_this_device: false
send_configuration_to_device: true
send_configuration_to_device_using: ENABLE_USING_COA
coa_source_host: ise1.cisco.com
include_when_deploying_sgt_updates: true
exec_mode_username: dev1
exec_mode_password: Cisco123
enable_mode_password: Cisco123