<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Service Through Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4417584#M567836</link>
    <description>&lt;P&gt;I think&amp;nbsp;&lt;A id="link_16" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/42069" target="_self" aria-label="View Profile of mohanB"&gt;&lt;SPAN class=""&gt;mohanB&lt;/SPAN&gt;&lt;/A&gt; is correct. That is, ISE can learn the users' IP addresses passively through the Passive Identity service.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 01:07:50 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2021-06-14T01:07:50Z</dc:date>
    <item>
      <title>Identity Service Through Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4414791#M567747</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some suggestions / guideline regards to one of my query as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my client wants to use Cisco ISE to be identity provider for some of local firewalls ( FMC ) to allow AD Based rule for the Firewalls Managed by FMC. What I need to configure for this to happen ? Can you suggest ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently there are AD Connection with ISE for other solutions ( anyconnect ) , but firewalls they are trying to use has no relation with ISE for any solution perspective. For those Firewalls they just want to use ISE as Identity Provider so that they can use AD Based Rule at those Firewalls.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 15:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4414791#M567747</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2021-06-08T15:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Service Through Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4414927#M567748</link>
      <description>&lt;P&gt;Recently had to do this. In brief, you can use ISE-PIC (can be separate node or can be enable in existing node as a persona), which basically is identity source, on the backend it can integrate with ADs using WMI (few other methods are out there as well) to receive user login information, which then it can use to build user id to IP address mapping. This information then can be passed to FMC using pxGrid protocol. Once you have the FMC configured with realms and can download users and groups, and have user-IP mapping from pxGrid. Then you can code firewall rule using AD user and group. Once traffic matches the identity rule, it looks up to see if it matches the identity conditions and access rule can be coded to allow or deny that traffic.&lt;/P&gt;&lt;P&gt;Obviously as always, better to plan the resources need appropriately and if separate ISE-PIC node needs to be deployed or not&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 19:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4414927#M567748</guid>
      <dc:creator>mohanB</dc:creator>
      <dc:date>2021-06-08T19:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Service Through Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4416417#M567782</link>
      <description>&lt;P&gt;Is ISE aware of all user session’s IP addresses? (E. g. by means of 802.1X) If not, FMC should query the AD and use AD directly as identity source. Thus, pxGrid may not be necessary &amp;nbsp;between ISE and FMC.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 21:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4416417#M567782</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2021-06-10T21:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Service Through Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4416449#M567792</link>
      <description>&lt;P&gt;Hello Peter,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How I can validate below ? I know that ISE I am using is used for one existing VPN as Identity Sources ( i.e FMC - FMC is the manager for VPN Firewall )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Is ISE aware of all user session’s IP addresses? "&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 21:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4416449#M567792</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2021-06-10T21:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Service Through Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4417584#M567836</link>
      <description>&lt;P&gt;I think&amp;nbsp;&lt;A id="link_16" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/42069" target="_self" aria-label="View Profile of mohanB"&gt;&lt;SPAN class=""&gt;mohanB&lt;/SPAN&gt;&lt;/A&gt; is correct. That is, ISE can learn the users' IP addresses passively through the Passive Identity service.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 01:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-service-through-cisco-ise/m-p/4417584#M567836</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-06-14T01:07:50Z</dc:date>
    </item>
  </channel>
</rss>

