<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDA AND ISE PIC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708932#M557823</link>
    <description>&lt;P&gt;Thanks, Jason... !&lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2018 16:02:09 GMT</pubDate>
    <dc:creator>ffischer</dc:creator>
    <dc:date>2018-09-18T16:02:09Z</dc:date>
    <item>
      <title>CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476620#M557816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Regarding the identity based FW (ASA), I have a customer who is in great need for either CDA to support AD-2016 or use ISE-PIC to support the radius connector/integraton with ASA. Please can you share when these features will be available.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476620#M557816</guid>
      <dc:creator>muath salman</dc:creator>
      <dc:date>2020-02-21T18:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476621#M557817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We cannot discuss roadmap in this forum.&amp;nbsp; You will need to reach out to your product management team to discuss when the CDA RADIUS interface will become available in ISE-PIC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 14:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476621#M557817</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-10-24T14:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476622#M557818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Hello Timothy&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;thanks for your reply.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I was reading on ISE-PIC and I saw -&amp;nbsp; "&lt;SPAN style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;ISE PIC is a lightweight ISE version which focuses on Passive ID features."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Would you know if the ISE version 2.0.0.306 (ISE-VM-K9) ADE-OS Version 2.3.0.17 should be able to replace the CDA? Currently our ASA 5555 has the CDA as the Ad-agent. But when I replace the CDA with the ISE on the ASA, we I am&amp;nbsp; getting this message:&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;ASA# test aaa-server ad-agent ISE-SERVER host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;INFO: Attempting Ad-agent test to IP address &amp;lt;x.x.x.x&amp;gt; (timeout: 12 seconds) &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;&lt;STRONG&gt;ERROR: Ad-agent Server not responding: No response from server&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;ISE and ASA can ping each other ok. Also mapping on ISE is working OK (I see the logs)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;So, should this be working on ISE (not on ISE-PIC)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;&lt;STRONG&gt;thank you&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 19:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476622#M557818</guid>
      <dc:creator>alexeradze</dc:creator>
      <dc:date>2017-11-20T19:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476623#M557819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-PIC was introduced as part of ISE version 2.2.&amp;nbsp; You will need a minimum of ISE 2.2 to use the enhanced PassiveID features but remember, ISE 2.2 or 2.3 does not currently have the CDA RADIUS interface the ASA needs to get identity information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 19:45:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476623#M557819</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-11-20T19:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476624#M557820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Timothy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 22:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3476624#M557820</guid>
      <dc:creator>alexeradze</dc:creator>
      <dc:date>2017-11-20T22:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708541#M557821</link>
      <description>&lt;P&gt;I have a client who would need this feature as well ...&lt;/P&gt;
&lt;P&gt;Any news about this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does ISE 2.4 have the RADIUS interface from CDA to provide mappings ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or has pxGrid found its way to the ASA feature list ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 07:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708541#M557821</guid>
      <dc:creator>ffischer</dc:creator>
      <dc:date>2018-09-18T07:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708863#M557822</link>
      <description>I checked with our SMEs on this and its no and no. We are working on adding a RADIUS interface to ISE passive ID but cannot discuss roadmap feature on a public forum. please reach out through our product management team through sales channel&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Sep 2018 15:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708863#M557822</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-18T15:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708932#M557823</link>
      <description>&lt;P&gt;Thanks, Jason... !&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 16:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/3708932#M557823</guid>
      <dc:creator>ffischer</dc:creator>
      <dc:date>2018-09-18T16:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4792162#M580409</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here is a solution to integrate new ISE versions with CDA: &lt;A href="https://www.isecdabroker.com" target="_self"&gt;https://www.isecdabroker.com&lt;/A&gt;&lt;BR /&gt;It really works!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 12 Mar 2023 18:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4792162#M580409</guid>
      <dc:creator>Maksim Tikunov</dc:creator>
      <dc:date>2023-03-12T18:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4792178#M580414</link>
      <description>&lt;P&gt;As CDA protocol was removed from ISE roadmap, we have also built app, that allows ASA to read identities from ISE. It is based on pxGrid v2 and reverse engineered CDA protocol. Thus no need for Cisco CDA product. Works great in full download mode.&lt;/P&gt;
&lt;P&gt;Available for others as product.&lt;/P&gt;
&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 20:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4792178#M580414</guid>
      <dc:creator>mbisko</dc:creator>
      <dc:date>2023-03-12T20:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4893748#M583104</link>
      <description>&lt;P&gt;Hello, Mbisko! Dou you have some procedure or link to share witch us how to solve this problem? Here I have Cisco ASA witch CDA and our ADs can't be update.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4893748#M583104</guid>
      <dc:creator>fernandobvds</dc:creator>
      <dc:date>2023-07-27T13:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4893946#M583108</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;you need Cisco ISE with pxGrid enabled and properly licensed to share identites. You also need at least one Linux server (rather two for HA) with dotNet support installed on. Our service will maybe run on Windows but it was probably never tested.&lt;/P&gt;
&lt;P&gt;The service connects to the pxGrid and receives information about service points on the Cisco ISE to reach two services for full identity database update and incremental identity updates. The service needs username/password authentication enabled for pxGrid and does not support certificate based authentication.&lt;/P&gt;
&lt;P&gt;These two sources of information are translated into ASA language. What our service does not purpously support is identity update which is generated by the ASA. It drops all these updates. If you need this functiopnality we would need some time to code and test. The scenario we built this service for, needs these ASA sourced identity updates blocked. We support IPv6 updates and our code fixes several Cisco ISE issues where some identity updates are malformed time to time. We support only "full download mode", not "on demand mode". (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/aaa-idfw.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/aaa-idfw.html&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;If you are interested, I can provide you with the code and demo license and help you configure it.&lt;/P&gt;
&lt;P&gt;Some information (probably not very usefull for you:-)) can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.alefnula.com/identity-bridge.c-591.html" target="_blank"&gt;https://www.alefnula.com/identity-bridge.c-591.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;BR, Martin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 16:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4893946#M583108</guid>
      <dc:creator>mbisko</dc:creator>
      <dc:date>2023-07-27T16:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4894203#M583112</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Do You are a company thar implement this solution?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 00:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4894203#M583112</guid>
      <dc:creator>fernandobvds</dc:creator>
      <dc:date>2023-07-28T00:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: CDA AND ISE PIC</title>
      <link>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4894844#M583123</link>
      <description>Yes, of course. It is running for more than 18 months at one of the biggest banks in the Czech Republic without any issue. It serves identities to two VPN gateways and user firewall for LAN and WiFi.&lt;BR /&gt;&lt;BR /&gt;Martin&lt;BR /&gt;</description>
      <pubDate>Fri, 28 Jul 2023 11:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cda-and-ise-pic/m-p/4894844#M583123</guid>
      <dc:creator>mbisko</dc:creator>
      <dc:date>2023-07-28T11:52:16Z</dc:date>
    </item>
  </channel>
</rss>

