<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE FMC pxgrid integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4544465#M572569</link>
    <description>&lt;P&gt;It's important to note that static IP/Subnet-SGT mappings are published to pxGrid subscribers via the SXP topic, so all of the SXP configuration has to be done in order for those bindings to be shared.&lt;/P&gt;
&lt;P&gt;Please confirm that you have configured all of the necessary elements as per the following example guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2020/04/24/ftd-static-ip-sgt-mapping/" target="_blank"&gt;https://integratingit.wordpress.com/2020/04/24/ftd-static-ip-sgt-mapping/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The same configuration works as expected in my lab using ISE 3.0p4 and FMC 7.0.1&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 22:13:58 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2022-02-02T22:13:58Z</dc:date>
    <item>
      <title>ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4543966#M572558</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have integrated&amp;nbsp; SGT Pxgrid with FMC and ISE in order to share SGT/IP Mapping&lt;/P&gt;&lt;P&gt;when i configure manually an SGT/IP Mapping on ISE, this entry is not pushed automatically to FMC unless&amp;nbsp; restarting ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 11:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4543966#M572558</guid>
      <dc:creator>AirBorn</dc:creator>
      <dc:date>2022-02-02T11:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4544032#M572561</link>
      <description>&lt;P&gt;&lt;SPAN&gt;when i configure manually an SGT/IP Mapping on ISE, this entry is not pushed automatically to FMC unless&amp;nbsp; restarting ISE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Please share versions of ISE/FMC; Is the pxgrid client showing as ON in ISE? When you test integration from FMC what do the logs say(Settings-&amp;gt;Integration-&amp;gt;Identity Sources:Test)? In ISE download and take a look at the pxgrid logs: Operations-&amp;gt;Troubleshoot-&amp;gt;Download Logs-&amp;gt;Select the PxGrid node: PxGrid section contains several debug logs;&amp;nbsp; Those may help shed some light.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 12:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4544032#M572561</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-02-02T12:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4544465#M572569</link>
      <description>&lt;P&gt;It's important to note that static IP/Subnet-SGT mappings are published to pxGrid subscribers via the SXP topic, so all of the SXP configuration has to be done in order for those bindings to be shared.&lt;/P&gt;
&lt;P&gt;Please confirm that you have configured all of the necessary elements as per the following example guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2020/04/24/ftd-static-ip-sgt-mapping/" target="_blank"&gt;https://integratingit.wordpress.com/2020/04/24/ftd-static-ip-sgt-mapping/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The same configuration works as expected in my lab using ISE 3.0p4 and FMC 7.0.1&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 22:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4544465#M572569</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-02-02T22:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4793473#M580455</link>
      <description>&lt;P&gt;Hi Greg&lt;/P&gt;
&lt;P&gt;it's a bit confusing as previously i thought that IP-SGT mappings learned via SXP by ISE simply can be published to PxGrid for its consumers to learn that mappings w/o the need to additionally configure SXP pipe between PxGrid consumer &amp;amp; ISE:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_pxgrid.html" target="_blank" rel="noopener"&gt;Cisco Identity Services Engine Administrator Guide, Release 3.0 - pxGrid [Cisco Identity Services Engine] - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Publish and subscribe to SXP bindings (IP-SGT mappings) through pxGrid. For more information about SXP bindings, see the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;Security Group Tag Exchange Protocol&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section in the Segmentation chapter of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" href="https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-installation-and-configuration-guides-list.html" target="_blank" rel="noopener"&gt;Cisco ISE Administrators Guide&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;what is the benefit from above publishing if admin still need to configure SXP communication between PxGrid consumer &amp;amp; ISE?&lt;/P&gt;
&lt;P&gt;also triggered drawback is that if static IP-SGT mapping must be consumed by PxGrid subscriber, it's mandatory to configure SXP session between PxGrid subscriber &amp;amp; IP-SGT-mapping provider/speaker . could u pls share documents where this restriction/limitation is announced?&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 10:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4793473#M580455</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-03-14T10:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4794131#M580479</link>
      <description>&lt;P&gt;Information about how the FMC consumes SGT bindings from ISE and how to configure it can be found in the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/730/management-center-device-config-73/identity-ise.html?bookSearch=true#id_111604" target="_blank" rel="noopener"&gt;Cisco Secure Firewall Management Center Device Configuration Guide&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;As stated in the guide regarding the required option&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;Publish SXP Bindings on PxGrid&lt;/EM&gt;&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"This option makes ISE send the SGT mappings out using SXP. You must select this option for the&amp;nbsp;&lt;SPAN class="ph"&gt;threat defense&lt;/SPAN&gt;&amp;nbsp;device to “hear” anything from listing to the SXP topic. This option must be selected for the&amp;nbsp;&lt;SPAN class="ph"&gt;threat defense&lt;/SPAN&gt;&amp;nbsp;device to get static SGT-to-IP address mapping information. It is not necessary if you simply want to use SGT tags defined in the packets, or SGTs that are assigned to a user session."&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 23:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4794131#M580479</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-03-14T23:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4794220#M580482</link>
      <description>&lt;P&gt;Yes. i saw it. Is that statement specific to FMC/FTD, or other ISE's PxGrid consumers (like CheckPoint FW) r required to have SXP-peering with ISE as well? Other words is having both PxGrid consumer role &amp;amp; SXP-peer of ISE rule of thumb for the IP SGT static mappings to be learnt?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 07:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4794220#M580482</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-03-15T07:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4795060#M580515</link>
      <description>&lt;P&gt;Static IP-SGT mappings are only published by ISE via the SXP Topic. For another consumer to learn these, they would need to support the ability to subscribe to the SXP Topic.&lt;/P&gt;
&lt;P&gt;To be clear, this is&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; a real SXP peering. As the documentation says:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"This does not have to be a real device, you can even use the management IP address of the&amp;nbsp;&lt;SPAN class="ph"&gt;threat defense&lt;/SPAN&gt;&amp;nbsp;device. The table simply needs at least one device to induce ISE to publish the static SGT-to-IP address mappings."&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 21:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4795060#M580515</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-03-15T21:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE FMC pxgrid integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4795263#M580524</link>
      <description>&lt;P&gt;Greg, pardon for being annoying around it but i really dont understand now how does it work &amp;amp; how it relates to PxGrid.&lt;/P&gt;
&lt;P&gt;Does IP-SGT static mapping get populated via SXP-topic in PxGrid whilst subject mapping's consumer (PxGrid subscriber) must be declared in ISE's SXP-peer-list to make ISE as PxGrid controller aware about consumer's IP-SGT-mapping learning need?&lt;/P&gt;
&lt;P&gt;or does it work different way?&lt;/P&gt;
&lt;P&gt;P.S. on&amp;nbsp;&lt;A href="https://developer.cisco.com/docs/pxgrid/#!technical-overview/technical-overview" target="_blank" rel="noopener"&gt;Technical Overview - pxGrid API - Document - Cisco Developer&amp;nbsp;&lt;/A&gt;i've read that ISE'simplementation of "&lt;SPAN&gt;pxGrid will use port 8910 on ISE for pxGrid-related REST and Websocket communication" which seems to be owned by STOMP-speaking program module or whatever it is... is it up-to-date for ISE 3.X?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;P.P.S. it's very pity CCO doesnt have documents clearly explaining this interoperation :0(&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 15:21:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-fmc-pxgrid-integration/m-p/4795263#M580524</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-03-17T15:21:05Z</dc:date>
    </item>
  </channel>
</rss>

