<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Prime integration superuser admin in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4049441#M559032</link>
    <description>&lt;P&gt;Marvin, thank you very much!&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2020 18:28:36 GMT</pubDate>
    <dc:creator>Murinos</dc:creator>
    <dc:date>2020-03-20T18:28:36Z</dc:date>
    <item>
      <title>ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038441#M558489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;didn't find the answer anywhere so would like to ask if someone knows why the Prime needs a superuser admin for the integration. The Prime server should only read some data from ISE, so I thought a Read-only admin would be enough.&lt;/P&gt;&lt;P&gt;Many customers have problem to add the superuser rights to such a user so a good explanation would be great.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 10:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038441#M558489</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2020-03-02T10:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038487#M558490</link>
      <description>Are you asking about integration with Active Directory (AD)? 
If so, no AD admin user account is required - only one with the ability to join the ISE nodes to the domain as domain computers and then only during initial configuration.</description>
      <pubDate>Mon, 02 Mar 2020 11:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038487#M558490</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-02T11:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038529#M558492</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;thanks for the reply. I am talking about the integration of Cisco ISE with the Prime infrastructure.&lt;/P&gt;&lt;P&gt;A local admin account in ISE is required and that admin has to be superuser. I do not understand why such privileges are needed.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 13:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038529#M558492</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2020-03-02T13:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038565#M558493</link>
      <description>I suspect it is because the developers did not take the trouble to dig deeply into the Role-Based Access Control (RBAC) capabilities of ISE. Rather than define the exact data fields/types and roles necessary to integrate, it was easier for them to just say to use a superuser account.</description>
      <pubDate>Mon, 02 Mar 2020 13:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038565#M558493</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-02T13:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038583#M558495</link>
      <description>&lt;P&gt;Thanks Marvin, that's what I thought.&lt;/P&gt;&lt;P&gt;That's not good and I understand that the customers don't like it.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 14:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4038583#M558495</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2020-03-02T14:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048650#M559009</link>
      <description>&lt;P&gt;Have same question here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer with highly secure environment doesn't want to allow any unnecessary superuser access to ISE . Especially since there is no explict documentation neither in ISE configuration guides or PI configuration guides...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also there is no explanation, how does PI interacts with ISE - ports or protocols we should open on firewalls seems to be investigated by packet capture...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 13:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048650#M559009</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-03-19T13:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048660#M559010</link>
      <description>&lt;P&gt;Ports and protocols I can answer - it is tcp/443 transporting TLS 1.2 (unless you have some really old unsupported releases in which case it's TLS 1.1).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 13:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048660#M559010</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-19T13:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048664#M559011</link>
      <description>&lt;P&gt;Thanks a lot for that!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any references in documentation? Unfortunately, we can't just refer to Cisco community, customer's security department need a proof for every ACL created...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 13:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048664#M559011</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-03-19T13:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048726#M559012</link>
      <description>&lt;P&gt;The ISE server is added from the PI side. When you do that, the port is shown in the GUI:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE-PI Integration.PNG" style="width: 644px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69446i21BAB86674D7C9CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE-PI Integration.PNG" alt="ISE-PI Integration.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally you can easily run tcpdump on the ISE node (Operations &amp;gt; Troubleshoot &amp;gt; Diagnostic Tools) and see the traffic. Packet capture doesn't lie, no matter what the guides show (or don't show).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE-PI pcap.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69449i2F517C30F29BE050/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE-PI pcap.PNG" alt="ISE-PI pcap.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 14:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4048726#M559012</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-19T14:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4049441#M559032</link>
      <description>&lt;P&gt;Marvin, thank you very much!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 18:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4049441#M559032</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-03-20T18:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4050784#M559085</link>
      <description>&lt;P&gt;Since ISE 2.0, the user could be one of the following ISE admin user roles:&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;PRE class=""&gt;SUPER_ADMIN,SYSTEM_ADMIN,MNT_ADMIN&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 20:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4050784#M559085</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-03-23T20:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062464#M559498</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Cisco TAC says that it is not possible:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;Please be advised that the credentials should be superuser credentials local to ISE. Otherwise, ISE integration does not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;May you please give any screenshots to proof it works? We have a ssh issue connecting PI to ISE(the reason to ask TAC for help) and we can't test it ourselves.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062464#M559498</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-04-09T07:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062926#M559508</link>
      <description>&lt;BLOCKQUOTE&gt;... &lt;SPAN style="font-family: inherit;"&gt;We have a ssh issue connecting PI to ISE(the reason to ask TAC for help) and we can't test it ourselves.&lt;/SPAN&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;PI does not connect to ISE via SSH AFAIK. Only Cisco DNA Center requires ssh to ISE.&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/api_ref_guide/api_ref_book/ise_api_ref_ch1.html" target="_blank"&gt;Introduction to the Monitoring REST APIs&lt;/A&gt;&amp;nbsp;is where we documented the admin role requirements due to &lt;SPAN&gt;CSCur87193, which is not customer visible due to lack of a release-note-enclosure&lt;/SPAN&gt;. We were supposed to be documented in ISE compatibility matrix but somehow the info lost and our BE is not regularly testing ISE integration with PI.&lt;/P&gt;
&lt;P&gt;IIRC we tested it successfully with ISE 2.0/2.1 and PI 3.1 in CY2016. As that is 4 years ago, the setup is no longer available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 16:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062926#M559508</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-04-09T16:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062938#M559509</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp; Thank you for clarification! That's inspiring. Will post what we'll be able to do.&lt;/P&gt;&lt;P&gt;SSH - my fault, I meant TLS of course.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 17:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4062938#M559509</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-04-09T17:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Prime integration superuser admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4180868#M563709</link>
      <description>&lt;P&gt;Hi hslai&lt;SPAN class=""&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;We made it work, thanks to you!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;We have added ISE to PI using MnT Admin user role instead of Super Admin.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 12:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prime-integration-superuser-admin/m-p/4180868#M563709</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-11-09T12:56:59Z</dc:date>
    </item>
  </channel>
</rss>

