MARS Device Groups

I am working with MARS 4.3.4 and have a question on what you can do with Device Groups. I don't see where they can be referenced in queries or rules. Am I missing something?

No, you're not. They're somewhat pointless really. You can create them, but they're only used to filter what is displayed, you still have to manually select each individual device in a query.
In other words, you can't create a report using a device group and expect future updates to the device group to show up in the report.
FWIW, there are lots of other "groups" like this too. Protego/Cisco seems to have forgotten the real value of making groupings like this.

Similar Messages

  • I see "Enrollment Settings" under device groups but it doesn't seem to do anything.  Is that normal?

    Hello, first time poster.
    I'm new to most things apple aside from basic use of ipads and iphones.  I was put in charge of the ipads for my school district and after some research and effort, I've gotten a mac server (on mavericks) up and running.
    I have setup an MDM, gotten the token, gotten the VPP, etc...
    Everything is working as it seems to be working.  But...
    In Device groups, under settings for a device group I see "Enrollment Settings" with things like "prompt user to enroll device" and "Supervise (IOS only)".  So I added a device to a new group, reset the device in question and nothing.  The settings appeared to do nothing.  Is that normal or am I missing something?

    Which version of Server.app?  3.1.2?
    Verifty local DNS services.  Invalid DNS causes other OS X Server components to have issues.  You'll need DNS on your local network somewhere, whether that's served by OS X Server, or another DNS server doesn't matter.
    Launch Terminal.app from Applications > Utilities and issue the following harmless, diagnostic command:
    sudo changeip -checkhostname
    That'll require an administrative password for the sudo, might generate a one-time message about the use of sudo, and will then display some configuration information and then an indication that no changes are required, or that there are network or DNS issues.  If you're not in .local or .arpa, that'll usually give you a good view of your local network configuration.
    The device has to be enrolled with Profile Manager server.   How you do that depends on how you want to manage your devices.   There are various overviews of how this stuff works too, if you're getting started: here is one video.

  • Delivery Assignment to Device group in standalone deployment?

    Hi,
    I am using the standalone deployment of SAP AII 2.1. I have the following two queries regarding assignment of deliveries to device groups.
    1. I am able to assign the same delivery to multiple device groups with same business roles as well as different business roles at the same time.
    For example, I am assigning the delivery to a device group that handles tag commissioning and I also assign the same delivery to a device group that handles the loading at the same time. Is this the correct behavior?
    Or is it that once a delivery is assigned to a device group, it should be first processed by that device group or unassigned before the same delivery can be assigned to a different device group?
    If this is the case, then is there any configuration setting in AII that can control the delivery assignment to device groups?
    2. Logically I believe that only one delivery can be assigned to a device group.
    I assign a delivery to a device group. Then I immediately assign another delivery to the same device group. I believe that the first delivery gets unassigned from the device group, but there is no message to this effect
    Again is there any configuration setting for handling this situation?
    Regards,
    Dhananjay

    What you are deploying is a Client Settings policy, not the client itself. This is akin to a Group Policy Object being linked to an OU. The machines in the collection which already have the ConfigMgr client will process those policies, but additional non-client
    machines added to the collection will not automatically install the client.
    As Torsten indicated, you can deploy the client to these machines using the manual client push method.  Simply right click on the clients themselves (or the collection) and select Install Client.  If doing it at the collection level, I recommend
    against selecting "Always install the client software" in the wizard as it will force an unnecessary repair of the existing ConfigMgr clients. I would recommend testing this on one machine in the collection in question before attempting to do them in bulk.
    Note that this requires that a Client Push Installation account be configured (Administration > Site Configuration > Sites > Client Installation Settings >  Client Push Installation > Accounts tab) which has admin rights on the clients.
    You *DO NOT need to enabled site-wide client push installation* to be able to use the Install Client method in the console. Enabling this will force the client to attempt installation on ALL systems that ConfigMgr sees.

  • Multiple Network Device Groups when importing to ISE using template

    I have a question about importing a group of network devices into ISE using the template provided. The template only has a single column for Network Device Groups - is there a way to import devices and include more than one NDG? For instance, the NDG's we use are "Device Type" and "Location". I'd like to include both when doing my import and I've tried multiple ways to seperate the two strings within the column (comma's colons, semi-colons, spaces, pipes, tabs, etc), but i always get an error message that "NDG group does not exist". I also tried adding a new column into the template, but that just plain failed to import.
    If there is any way to do this, I would appreciate any advice on how - I have to add about 40 devices per week to our ISE deployment and I'd rather not have to go in and add any parameters manually if it can be helped. Thanks very much!
    Ross
    BTW, we are running ISE ver 1.1.2 in case it is relevant.             

    Yes, you can do it. You have to use the pipe "|" to separate the groups. But please notice you must create the network device groups in advance.
    For example, I have the following groups in my csv file to import a lot of network devices
    Device Type#All Device Types#SWITCHES#375O-X|Location#All Locations#PERU#LIMA
    But as a pre-requisite I have to create the network device groups.
    If you have lots of network device groups, you can mass import them instead of creating them one by one.
    Please rate if it helps

  • Printer device group and a label format in SAP AII

    Hello @ all,
    I try to configure a SAP OER System with SAP AII. Now I should configure the label printing with the transaktion /AIN/ASGN_PRF_FORMAT. I must take a profile name, a printer device group and a label format. The problem is now, that I can't chose a printer device group and also I don't know the label format. Where can I adjust the printer device group and which label format must be in that field?
    Can anybody help me?
    Thank you.
    Peter

    Hi Peter,
    SAP AII sends the label format filename as part of the Command message xml to the printer during tag commissioning.
    I assume you have configured the label format filename for SAP_PRINT_PROFILE using transaction /AIN/ASGN_PRF_FORMAT - Assign Format to Printer and Profile
    Now you have to assign that profile to an ID type or GTIN, etc. using the menus under Profiles for Tag Commissioning and Label Printing.
    Once this configuration is done, the xml command message containing the element WriteTagData is sent to the printer RFC destination configured against the Device controller as an HTTP message.
    This command message will contain the label format and  field names - value pairs as per the SAP_PRINT_PROFILE.

  • Device group and applications affinity

    Hello all.
    I have some device groups created with CFS configured on them.
    I need to ensure that a clusterized application runs on the server that is primary for the device group. I need to set an affinity between the affinity and the device group/file system.
    The problem is that the SUNW.HAStoragePlus does not indicates the real primary for the device group, for example:
    # cldg status ufs_homedg
    Cluster Device Groups ===
    --- Device Group Status ---
    Device Group Name Primary Secondary Status
    ufs_homedg billbd2 billbd1 Online
    # clrg status ufsg-home-rg
    Cluster Resource Groups ===
    Group Name Node Name Suspended Status
    ufsg-home-rg billbd1 No Online
    billbd2 No Offline
    In this output, the resource group is online in billbd1 and the device group primary is billbd2.
    If I failover the resource group, the device group is switched also, but it seems that at startup, the resource group does not check who is the primary to start on that node.
    This means that the status of the resource group does not helps to identify who is the primary for a device group and I cannot use it for affinity configuration.
    ¿How can I ensure that an cluster application starts on the node who is primary for the device group on which the file system is created?
    I was thinking on a SUNW.gds for this purpose, but I wonder if there is another way.
    Thanks in advance.
    Edited by: Ivan.Ferreira on Jun 19, 2008 8:04 AM

    Hi Tim, thanks for your time.
    Yes, I'm using AffinityOn=TRUE. After some testings, I can see that the device group is switched at startup, but I don't know under which circunstances it does not.
    Also, I can force discrepancy with the device group and the resource group if a perform a cldg switch.
    So, if I run clrg switch, the device group is switched also. If I run cldg switch, the device group is switched but the HAStoragePlus resource does not.
    This means that HAStoragePlus cannot ensure that the node is the primary for a device group and cannot be used for affinity on applications.
    �What do you think?

  • 1) Device groups

    First question:
    Workstations (devices) are currently allocated under /Devices/Workstations to
    folders that represent the office location of the workstation.
    Is there a way to create device groups without removing the devices from their
    primary location-related folder?
    Is there a way to use AD device groups to assign bundles?
    What's the latest thinking on to how to apply a constraint on a bundle to apply
    both "user-membership-in-AD-group", and "device is approved for this app"?
    e.g. I know I can add "specified devices" as a requirement, but that demands
    adding individual workstations and I see no way to add device groups, which can
    be very tedious if I want, for example, "this app can install for these users
    on these 200 devices".
    Thanks.
    -- DE

    Originally Posted by DE
    thsundel wrote:
    > Yes, create a workstation group and add the computers you want as
    > members (they will not be removed from their "location-related" folder.
    OK, so I want to be sure that I am understanding ...
    Currently the workstations are in, say,
    /Devices/Workstations/bigcity1/desktops
    /Devices/Workstations/bigcity1/laptops
    /Devices/Workstations/bigcity2/desktops
    /Devices/Workstations/bigcity2/laptops
    They need to stay in those folders, for obvious reasons. And unfortunately,
    this will never match up to AD because it starts at the top level by
    differentiating between workstations & servers, while AD identifies "computers"
    that are placed into whatever AD structure you define.
    In any case: So I can create device groups that won't result in them being
    moved out of those folders?
    IOW, I could define a device group that contained the systems that were allowed
    to have a certain app installed, and that group membership won't disrupt the
    above folders?
    And are we talking about Dynamic device groups (which I've never used) or are
    there other regular "device groups" that don't just represent the structure above?
    Thanks again. I have a feeling that others before me have already requested an
    enhancement that device groups be an option in Requirements, since I think I've
    read discussions of these same issues here in the past.
    -- DE
    Yes, just create e "regular" Device Group where ever you want in the folder structure and add workstations as members.. You probably hava a test workstation that you can try with if your not confident.
    Thomas

  • SSL Accelerated Service and device groups

    I have a need to set up SSL accelerated services on a data center WAE and one edge WAE. In reading through the Cisco Wide Area Application Services SSL Application Optimiser Deployment Guide (2010), it states that best practice is to create an SSL device group and configure the SSL service and generate the keys through that group.
    Simple question:  Should only the data center WAE be placed in that group, or should also the edge WAE be in the group?  The devices are running 4.3.3.

    Only the data center wae's need to be placed in the SSL device group.
    Regards
    -Smita

  • ACS web interface hangs on Network Device Group

    We are facing problem of ACS web interface stop responding whenever a Network Device Group is edited/added/deleted. This happens regardless of whether the web interface is opened remotely or on the ACS server.
    The session needs to be killed and then have to wait several minutes before attempting to edit NDG (although new session to ACS can be opened up almost immediately).
    I have checked there are no proxy settings in the browser, no firewall in between, etc.
    ACS is installed on Windows 2003 Server Enterprise Edition with SP1.
    ACS installation on another server of same hardware specs and java version works fine. The difference is that the OS on the working ACS is Win 2K3 Ent Ed. without SP1. However, according to Cisco, WIN 2K3 Ent Ed with SP1 is a supported platform.
    My ACS version is 4.0(1) build 27.
    Any ideas?

    I assume you have a java runtime installed?
    alas in the "old days" you could troubleshoot this type of thing by looking in the windows registry. This is all internal to the ACS SQLAnywhere DB now :(
    Darran

  • In Profile Manager, Can I assign users to ONLY a specific Device Group?

    In profile Manager (Lion Server 10.7.3) I created DEVICE GROUPS per Lab, and each Lab has a manager. I want to give each manager permissions to see and manage ONLY their devices. Is this possible?

    I'm not sure this was ever designed to be user friendly as typically only Admins or those with elevated permissions would see these groups.  There isn't as far as I can see, any way to add this step within a Wokflow too, unless you're able to install
    some third party steps.
    Steven Andrews
    SharePoint Business Analyst: LiveNation Entertainment
    Blog: baron72.wordpress.com
    Twitter: Follow @backpackerd00d
    My Wiki Articles:
    CodePlex Corner Series
    Please remember to mark your question as "answered" if this solves (or helps) your problem.

  • AAA Device Groups

    Hi,
    I have configured a major networ device group under which have sub groups.
    If i want to configure for R/O users to give access to certain sub network groups, can i make a device filter and call that device filter for allowing the access? or it has to be a seperate rule for each of the network device group.
    Please let me know the best practice
    Thanks

    It seems you're running ACS 4.x. You're facing this issues because the key defined on the NDG level (XYZ network device group in your case) over-rides the key at the AAA client level.  Please make sure that you don't have different secret key on the AAA  client inside the NDG and on the NDG itself.
    Not assigned is working because there is no key defined in that NDG.
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/NetCfg.html#wp342738
    "Each device that is assigned to the Network Device Group will use the shared key that you enter here. The key that was assigned to the device  when it was added to the system is ignored. If the key entry is null, the AAA client key is used."
    ~BR
    Jatin Katyal
    **Do rate helpful posts**

  • Device group failback enabled

    Hey folks, is here someone who can tell me,
    what the device group failback enabled option mean.
    You could type the folowing comand:
    scconf -pv
    and it spits out the options:
    Device group name: categat-ora9-ms
    (categat-ora9-ms) Device group type: SDS
    (categat-ora9-ms) Device group failback enabled: no
    (categat-ora9-ms) Device group node list: cnode1, cnode2
    (categat-ora9-ms) Device group ordered node list: yes
    (categat-ora9-ms) Device group diskset name: categat-ora9-ms

    When a node mastering the disk group leaves the cluster, the disk group will failover to the Secondary. When the failed node (original primary) rejoins the cluster, the disk group can be mastered by the Secondary or by the original primary based on 'failback' property.
    If failback property is enabled, the disk group will become mastered by the original primary. If failback is disabled, the disk device group will continue to be mastered by the secondary. By default, failback is disabled.
    HTH.

  • WAAS Central Manager Policy Definitions across several device groups

    Hi there,
    I am trying to find a way to apply a custom application policy(s) to multiple device groups. ( not the AllDevicesGroup).
    I have not found a way to export or import the policy.
    Any help would be appreciated.
    Todd

    I have my "Core" WAE's in a separate device group to prevent them from recieving a policy or setting intended for Edge WAEs.  For example, If someone sets the assignment method to hash, I certianly dont want that pushed to my Core, ( using Mask assignment)
    However, a custom application definition WILL need to be applied to both Core and Edge WAE's. Therefore I need a way to create the policy for all devices group and copy out and apply selected custom policies to the Core device group as well.
    Problem:  I have QUALYS Vulnerability Scanners that wreak havoc on WAE's by opening 1000's of sessions and not propoerly closing them, causing TFO Overload conditions, throughout the network.
    Solution: create a custom policy to set Scanner IP action to pass-through. there are 30+ scanners so the match condition is lenthy and woudl be painful to build manually for each device group.
    new Problem: need to apply this to multiple device groups.

  • CSM per admin group using per device group

    I am looking to see if multiple admin and device groups can be created to limit certain administrators to administrate only certain devices but not others.
    For example:
    admin group "ag_na" (including user admin1 & admin2)  can make changes to device group "dg_na" containing (device 1, device 2) only
    admin group "ag_ca" (including user admin3 & admin4) can make changes to device group "dg_ca" containing (device30 & device31) only
    Any tips on if / how to do this?
    Thanks

    You can do it by integrating the CSM into an ACS v4.2 and doing RBAC. There you can define for which NDGs a user has which access policy.
    http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/4.1/installation/guide/aduser.html#wp1063220
    Unfortunately this is a short-therm solution as ACS v4.2 has been put to EoS and no real alternative methods are available today. Hopefully Cisco will come up with a new solution on the long-therm.

  • Device Group Profile Drops after changes are saved

    Why do Device Group Profiles drops after applying a change? Some will get it no problem but some lose the profile thus losing network connectivity then requiring manual intervention.

    Thanks to all who replied, however..
    If the settings were stored int he CPL file ( which would be very odd but there it is ) I would expect that I could create a CPL file with the settings I want on one computer, and copy them to the same folder on another computer whose settings I want to standardize in the domain, however, this does not appear to be the case. I copied the entire ..\Program Files\Quicktime folder from one computer which had the settings I wanted, to another computer which didn't. The settings did not follow the copied Quictime folder and contents, so, with all respect and gratitude due to those who replied, I don't think settings are stored in the CPL file or any other file in the Quicktime folder.
    In any case, I don't really care where they are stored, I just need a way to propagate a single set of settings across multiple computers in a domain. I've never run across an application before that was so reistant to this type of thing...
    Thanks again
    TimeTraveller..

Maybe you are looking for

  • Slow startup CC&B 2.3.1

    Anyone else out there seeing an extremely slow startup time with CC&B 2.3.1 (using RH Linux here, but have seen it on Windows servers as well, so I'm not so sure OS is really important here, but wanted to note it just in case). It shows the following

  • Reinstallation of CS3 on new Harddisk is not working

    My Mac got a new harddisk. The repair man copied all files (including applications) form the old one. Of course the applications are not working. I want to install CS3 (which I bought and have a serial number) onto the new harddisk but after starting

  • Sudo nvram boot-args='-v' not working in10.8

    I want to turn on verbose via terminal.  I used to use the above command in terminal.  however it does not seem to work in ML.  Has it changed?

  • Label and Caption Graphics Question

    I must be missing something because I can not get the small white boarder to disappear from the gauge label and caption.  I've tried every property node option - except apparently the correct one.  Can someone help get rid of the white boarder around

  • ABAP program to output data from SAP table to an XML format file?

    hello ABAP experts, Does anyone know how to output data from SAP table to an XML format file?  Would be appreciated if someone show the detailed sample codes and we will give you reward points! Thanks!