<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE-PIC support for multiple tenants with FMC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pic-support-for-multiple-tenants-with-fmc/m-p/3579767#M509058</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-PIC supports 100 DC today. FMC gets to know about the group mapping learnt from AD. &lt;/P&gt;&lt;P&gt;you can verify in ISE under live sessions and check&amp;nbsp; the&amp;nbsp; IP mapping which is sent to FMC via PxGrid. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find more details from the link here- &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jun 2018 15:24:37 GMT</pubDate>
    <dc:creator>Nidhi</dc:creator>
    <dc:date>2018-06-13T15:24:37Z</dc:date>
    <item>
      <title>ISE-PIC support for multiple tenants with FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-support-for-multiple-tenants-with-fmc/m-p/3579766#M509055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have multiple tenants (government agencies) that are managed by a single FMC (and multiple FTD instances per tenant).&amp;nbsp; Each tenant has overlapping addressing and NAT is used heavily to present FMC with unique address space as well as for routing their traffic up to a shared Internet Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a requirement to use identity-based AC policy rules in FMC/FTD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to provide user/IP mappings via ISE-PIC??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can a single ISE-PIC support AD Forest/Domain connections to multiple tenants??&lt;/P&gt;&lt;P&gt;How would ISE-PIC present the IP mappings?? (ie would it be the original un-NAT'd IP??).&amp;nbsp; If so, how does FMC interpret the potentially overlapping user/IP mappings from ISE-PIC if mapped to a single realm thats mapped to a single identity policy to a single AC policy??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and kind regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dave.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 13:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-support-for-multiple-tenants-with-fmc/m-p/3579766#M509055</guid>
      <dc:creator>dadelima</dc:creator>
      <dc:date>2018-06-13T13:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-PIC support for multiple tenants with FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-support-for-multiple-tenants-with-fmc/m-p/3579767#M509058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-PIC supports 100 DC today. FMC gets to know about the group mapping learnt from AD. &lt;/P&gt;&lt;P&gt;you can verify in ISE under live sessions and check&amp;nbsp; the&amp;nbsp; IP mapping which is sent to FMC via PxGrid. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find more details from the link here- &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active-Direct.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210522-Configure-ISE-2-2-PIC-with-Active…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 15:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-support-for-multiple-tenants-with-fmc/m-p/3579767#M509058</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-06-13T15:24:37Z</dc:date>
    </item>
  </channel>
</rss>

