<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 and Microsoft AD integration using LDAP-S in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097659#M560904</link>
    <description>Thanks. Is it Cisco recommended way of integrating with Microsoft AD using LDAP-S? I'm also looking for Cisco configuration guide if there is any...to understand what would be the impact to ISE on Certificate Mgmt, AuthC and AuthZ, as well as RSA SecureID (2FA).</description>
    <pubDate>Thu, 04 Jun 2020 14:51:18 GMT</pubDate>
    <dc:creator>Ping Zhou</dc:creator>
    <dc:date>2020-06-04T14:51:18Z</dc:date>
    <item>
      <title>ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097151#M560877</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the configuration on ISE for Active Directory integration, &lt;STRONG&gt;Administration &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Identity Management &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;External Identity Sources &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Active Directory&lt;/STRONG&gt;, I don't see the options to use "LDAP Secure" ( such as port 636). I assumed, with 2.6, ISE does support LDAPS for Microsoft AD, but can't find any configuration guide. Can anyone share some docs that cover how to setup ISE with LDAPS for Microsoft AD?, what's the certificate requirement? Any limitation on Authentication and Authorization? etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 20:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097151#M560877</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2020-06-03T20:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097407#M560889</link>
      <description>&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;AFAIK, the communication ports are fixed. We cannot change AD connector communication from LDAP 389 port to LDAPS 636 Port. &lt;/FONT&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Though it is LDAP, but all the attributes are encrypted.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;If you need LDAPS, configure a new external LDAP identity store on ISE and there you can use LDAPS port.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 07:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097407#M560889</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-06-04T07:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097659#M560904</link>
      <description>Thanks. Is it Cisco recommended way of integrating with Microsoft AD using LDAP-S? I'm also looking for Cisco configuration guide if there is any...to understand what would be the impact to ISE on Certificate Mgmt, AuthC and AuthZ, as well as RSA SecureID (2FA).</description>
      <pubDate>Thu, 04 Jun 2020 14:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4097659#M560904</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2020-06-04T14:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098276#M560939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325437"&gt;@Ping Zhou&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You need to choose Schema as 'Active Directory'. Then configure it like in the picture below.&lt;/P&gt;
&lt;P&gt;Make sure LDAP and ISE trust each other's certificate's CA certificates.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-06-05 at 7.29.25 PM.png" style="width: 581px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76147iB883039F5BF4B2A5/image-dimensions/581x751?v=v2" width="581" height="751" role="button" title="Screenshot 2020-06-05 at 7.29.25 PM.png" alt="Screenshot 2020-06-05 at 7.29.25 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 14:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098276#M560939</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-05T14:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098310#M560946</link>
      <description>Much appreciated for the info. Do yon know if there is any Cisco docs for this? The Cisco doc here (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html&lt;/A&gt;) doesn't mention any LDAP-S. Before I put this into production, I have to understand its behaviors and limitations as I mentioned above (if there is any). I plan to lab it out with the AD team, but also want to have some Cisco official recommendation, tech notes or something.&lt;BR /&gt;&lt;BR /&gt;Thanks again for sharing your config screenshot.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;,</description>
      <pubDate>Fri, 05 Jun 2020 14:34:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098310#M560946</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2020-06-05T14:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098311#M560947</link>
      <description>We are working on updating a public Doc on Integration with Secure LDAP server. At this point, I'd urge you to do extensive lab testing before rolling-out in production.</description>
      <pubDate>Fri, 05 Jun 2020 14:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4098311#M560947</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-05T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4173664#M563521</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have any updates regarding the public docs you mentioned?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 13:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4173664#M563521</guid>
      <dc:creator>Michael Kiessling</dc:creator>
      <dc:date>2020-10-26T13:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4297865#M565724</link>
      <description>&lt;P&gt;Just wondering if there is an update on this yet?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 18:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4297865#M565724</guid>
      <dc:creator>Kacey Wilson</dc:creator>
      <dc:date>2021-02-25T18:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4297876#M565726</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/23876"&gt;@Kacey Wilson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;it looks like that the answer is no ... please take a look at: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html#ID-1420-00000011" target="_blank" rel="noopener"&gt;ISE Installation Guide 3.0 - Node Ports&lt;/A&gt;., search for &lt;STRONG&gt;External Identity Sources and Resources (Outbound)&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4297876#M565726</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-25T19:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Microsoft AD integration using LDAP-S</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4692533#M577350</link>
      <description>&lt;P&gt;Is there any update on this?&lt;/P&gt;&lt;P&gt;If you use the standard way of joining the AD via &lt;STRONG&gt;Administration &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Identity Management &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;External Identity Sources &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Active Directory&lt;/STRONG&gt;, are you still only able to use port 389?&lt;/P&gt;&lt;P&gt;I am reading the Implementing and Configuring Cisco Identity Services Engine (SISE), and it says the way which is suggested above by configuring it via an LDAP external Identity Source has limitations:&lt;/P&gt;&lt;H2&gt;Active Directory and LDAP Comparison&lt;/H2&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;Active Directory&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;Rich attribute set&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Direct tie between ISE and AD&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Fast performance&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;ISE can join multiple directories&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Search up or down the tree&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Active Directory accessed as LDAP server&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;ISE can join multiple directories&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Slower performance&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Fewer attributes&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Search down the tree only&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;You can access the Active Directory database either as Active Directory or as an LDAP server. Both methods have their pros and cons:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;When you connect to Active Directory via the Active Directory method, you gain advantages due to the direct tie between the Cisco ISE and Active Directory—an extensive attribute range, good performance, and the ability to search up or down the tree. Starting from version 1.3, Cisco ISE can join multiple directories.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;When you connect to Active Directory as an LDAP server, you can join multiple directories. However, this method slows performance, offers fewer attributes, and supports only searching down the tree.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it not possible to join the domain via LDAPs via &lt;STRONG&gt;Administration &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Identity Management &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;External Identity Sources &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Active Directory&lt;/STRONG&gt;?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 23 Sep 2022 08:12:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-microsoft-ad-integration-using-ldap-s/m-p/4692533#M577350</guid>
      <dc:creator>axeleratorcisco</dc:creator>
      <dc:date>2022-09-23T08:12:28Z</dc:date>
    </item>
  </channel>
</rss>

