<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and Tenable Integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5128131#M589950</link>
    <description>&lt;P&gt;Anyone else having issues with the Tenable adapter showing "Unknown/Unreachable"? The status did show "Disconnected/Active" at one point so im not sure how it took a step back. I can not find ANY documentation on troubleshooting this.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2024 17:10:06 GMT</pubDate>
    <dc:creator>eric-stewart-13-ctr</dc:creator>
    <dc:date>2024-06-10T17:10:06Z</dc:date>
    <item>
      <title>ISE and Tenable Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5094247#M589318</link>
      <description>&lt;P&gt;I am having an issue with Cisco ISE and TenableSC integration. In Cisco documentation it reads that i need to upload the system and root certificates from TenableSC. By using:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;sudo scp /opt/sc/support/conf/TenableCA.crt [username]@[your ip address]:TenableCA.crt&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;sudo scp /opt/sc/support/conf/SecurityCenter.crt [username]@[your ip address]:SecurityCenter.crt&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My questions are: Do I have to upload any Cisco ISE certificates into Tenable? What happens is the TenableCA certificate is expired? Is there a way to regenerate it? Are both needed?&lt;/P&gt;&lt;P&gt;I am setting up the Tenable adapter in the TC-NAC section and am getting this error code:&lt;/P&gt;&lt;P&gt;"Error connecting to Tenable Security Center, Error establishing https connection: Received fatal alert: handshake_failure"&lt;/P&gt;&lt;P&gt;I am also getting an error when uploading the Root CA certificate from Tenable:&lt;/P&gt;&lt;P&gt;"This trust certificate does not contain basicConstraint extension set to CA."&lt;/P&gt;&lt;P&gt;Any help or guidance is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5094247#M589318</guid>
      <dc:creator>eric-stewart-13-ctr</dc:creator>
      <dc:date>2024-05-08T14:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Tenable Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5094953#M589337</link>
      <description>&lt;P&gt;I have never setup such an integration, but in any case, ISE is correct: if a certificate claims to be the "Root CA" then it must have the&amp;nbsp;&lt;SPAN&gt;basicConstraint extension set to CA. Perhaps the cert you're trying to import into ISE is not the Tenable Root CA, but rather, the Tenable system certificate (i.e. the cert with which tenable identifies itself). You must not install any non-CA certs into the ISE Trust Center - instead, you must find out which CA (or CA chain) is involved in creating/signing the Tenable System cert, and then install that in ISE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for the question of whether to install ISE cert in tenable, it depends what kind of a connection is used - who initiates the connection? Is it ISE or Tenable? In most web-based systems, it's always the client who needs to check whether it trusts the server (and not the other way around) - the trust can be computed by having the CA (chain) installed in your trust store of the server you're attempting to connect to.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 05:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5094953#M589337</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-09T05:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Tenable Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5128131#M589950</link>
      <description>&lt;P&gt;Anyone else having issues with the Tenable adapter showing "Unknown/Unreachable"? The status did show "Disconnected/Active" at one point so im not sure how it took a step back. I can not find ANY documentation on troubleshooting this.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 17:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5128131#M589950</guid>
      <dc:creator>eric-stewart-13-ctr</dc:creator>
      <dc:date>2024-06-10T17:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Tenable Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5154639#M591024</link>
      <description>&lt;P&gt;Anyone see this issue yet with a Tenable.SC and Cisco ISE integration. Tenble.SC version: 6.3. Cisco ISE 3.1 P8&lt;BR /&gt;&lt;BR /&gt;2024-08-01 16:31:30.063&lt;BR /&gt;&amp;lt;adapter&amp;gt;&lt;BR /&gt;90d0b7e3-9884-483e-b35f-63506e513ecd&lt;BR /&gt;Tenable Security Center&lt;BR /&gt;VA Failure&lt;BR /&gt;ehuisepsn02&lt;BR /&gt;&amp;lt;MAC&amp;gt;&lt;BR /&gt;&amp;lt;IP&amp;gt;&lt;BR /&gt;Scan failed: Error in connecting to host: 403 Forbidden&lt;BR /&gt;2024-08-01 16:29:01.029&lt;BR /&gt;&amp;lt;adapter&amp;gt;&lt;BR /&gt;90d0b7e3-9884-483e-b35f-63506e513ecd&lt;BR /&gt;Tenable Security Center&lt;BR /&gt;VA request submitted to adapter&lt;BR /&gt;ehuisepsn02&lt;BR /&gt;&amp;lt;MAC&amp;gt;&lt;BR /&gt;&amp;lt;IP&amp;gt;&lt;BR /&gt;VA request submitted to adapter for processing&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 16:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5154639#M591024</guid>
      <dc:creator>eric-stewart-13-ctr</dc:creator>
      <dc:date>2024-08-01T16:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Tenable Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5163328#M591314</link>
      <description>&lt;P&gt;For anyone looking this up in the future, I was able to solve this by changing the&amp;nbsp;&lt;SPAN&gt;SCAN_DEFAULT_SCAN_TIMEOUT parameter value (under /opt/sc/src/) to 43200 on Tenable.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This information is in the Admin guide but it was easily missed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 16:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-tenable-integration/m-p/5163328#M591314</guid>
      <dc:creator>eric-stewart-13-ctr</dc:creator>
      <dc:date>2024-08-20T16:35:00Z</dc:date>
    </item>
  </channel>
</rss>

