<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Integration with Umbrella in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587852#M520682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like Umbrella relies on the WLC providing the group information to it, so that it confirms which profile a user is in, but I guess ISE can not populate this on the WLC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Oct 2017 10:56:05 GMT</pubDate>
    <dc:creator>robinwhi</dc:creator>
    <dc:date>2017-10-19T10:56:05Z</dc:date>
    <item>
      <title>ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587850#M520676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am interested to know if ISE can be used to control policy within Umbrella. Umbrella can hold profiles for different user groups for, say, corporate and guest users. If a guest user connects via a WLC can ISE provide the profile details to Umbrella so that their DNS access is limited to a subsection of URL destinations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Oct 2017 09:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587850#M520676</guid>
      <dc:creator>robinwhi</dc:creator>
      <dc:date>2017-10-19T09:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587851#M520680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No current integration that I know of but will double check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please reach out to umbrella team for this enhancement&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Oct 2017 10:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587851#M520680</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-19T10:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587852#M520682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like Umbrella relies on the WLC providing the group information to it, so that it confirms which profile a user is in, but I guess ISE can not populate this on the WLC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Oct 2017 10:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587852#M520682</guid>
      <dc:creator>robinwhi</dc:creator>
      <dc:date>2017-10-19T10:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587853#M520684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware of this integration or what group you’re referring to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best way for this to work is for umbrella to be able to consume pxgrid information for a scalable group tag to use in its policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please reach out to Umbrella team to work with ISE team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently checking with our product managers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Oct 2017 11:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587853#M520684</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-19T11:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587854#M520686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also reached out to our PM &lt;A href="https://community.cisco.com//u1/80492"&gt;enoy&lt;/A&gt; to see if something like this exists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Oct 2017 20:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587854#M520686</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-19T20:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587855#M520687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are working with Umbrella team but nothing which can be discussed at this time in public forum.&amp;nbsp; We do work indirectly today via RADIUS and pxGrid.&amp;nbsp; For example, users can be authorized to WLC and WLC integrate role assignments to Umbrella.&amp;nbsp; Similarly, ISR can receive Passive/Active identity via pxGrid and communicate that for Umbrella integration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 15:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3587855#M520687</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-20T15:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3695734#M520690</link>
      <description>&lt;P&gt;Craig, Do you have any updates for this?&amp;nbsp; I do have ISE and WLC (8.5) and would like to see deeper integration.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 19:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3695734#M520690</guid>
      <dc:creator>r_wideman</dc:creator>
      <dc:date>2018-08-27T19:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3697483#M520691</link>
      <description>&lt;P&gt;I would suggest to check out materials such as&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-4/b_cisco_umbrella_wlan_integration_guide.html" target="_blank"&gt;Cisco Umbrella WLAN Integration Guide - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 02:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3697483#M520691</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-08-30T02:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with Umbrella</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3904230#M520694</link>
      <description>&lt;P&gt;The Radius and WLC route seems to only work if you're pointing users to the cloud DNS&amp;nbsp;IP addresses 208.67.220.220 &amp;amp; 208.67.222.222, or forcing them to the cloud IPs using FORCED mode. Most of my customers are going the local Umbrella VA route and there doesn't appear to be a way to "tell" the WLC that the local VAs the users are hitting are actually Umbrella servers. We're still testing this, but not looking good so far...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/6-local-dns-forwarding" target="_blank"&gt;https://docs.umbrella.com/deployment-umbrella/docs/6-local-dns-forwarding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 02:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-umbrella/m-p/3904230#M520694</guid>
      <dc:creator>riwakefi</dc:creator>
      <dc:date>2019-08-07T02:50:16Z</dc:date>
    </item>
  </channel>
</rss>

