<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Security manager Integration with Cisco ISE for Security group Tag resolution in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3210027#M905439</link>
    <description>&lt;P&gt;It could be a bug / TLS compatibility issue. I'd recommend opening a TAC case since the ISE compatibility matrices don't list CSM (any version) as compatible despite what the CSM documentation indicates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had the same thing a while back with ISE and Prime Infrastructure. ISE (2.0 if I recall correctly) locked down TLS to 1.2 only while PI was still only able to talk TLS 1.1. It wasn't until PI (3.0 or 3.1 if I recall correctly) added TLS 1.2 support that integration worked once again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2017 02:43:58 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-11-03T02:43:58Z</dc:date>
    <item>
      <title>Cisco Security manager Integration with Cisco ISE for Security group Tag resolution</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3208770#M905437</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to&amp;nbsp; integrate Cisco CSM to ISE so that I can resolve the security group tags from CSM.&lt;/P&gt;
&lt;P&gt;I understand that in order to to be able to retrieve the group tags with a search name/tag in "Security group selector" we need to configure ISE Settings under "CSM &amp;gt;Tools &amp;gt;Security Manager Administration &amp;gt; ISE Settings"&lt;/P&gt;
&lt;P&gt;This is as per Cisco's Documention for CSM:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/4-7/user/guide/CSMUserGuide/syspage.html#34637" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/4-7/user/guide/CSMUserGuide/syspage.html#34637&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when I enter the ISE IP and Credentials in this page and click on Test Connectivity, it fails and give an error message "Unable to establish the connection. Please verify that the IP address, username, password are correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My first thought was that CSM was failing to communicate with ISE. So, I checked if there was any firewall block for this communication. There wasn't any firewall block for this. I did a packet capture and found that CSM is trying to communicate with ISE on port 443. After the initial TCP handshake, I get a handshake failure for TLS v1.2 from ISE and then the connection is torn down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to understand if there is any configuration needed on ISE for this? Any help would be appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Rohit.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3208770#M905437</guid>
      <dc:creator>rohitbhanu009</dc:creator>
      <dc:date>2020-02-21T14:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security manager Integration with Cisco ISE for Security group Tag resolution</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3210027#M905439</link>
      <description>&lt;P&gt;It could be a bug / TLS compatibility issue. I'd recommend opening a TAC case since the ISE compatibility matrices don't list CSM (any version) as compatible despite what the CSM documentation indicates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had the same thing a while back with ISE and Prime Infrastructure. ISE (2.0 if I recall correctly) locked down TLS to 1.2 only while PI was still only able to talk TLS 1.1. It wasn't until PI (3.0 or 3.1 if I recall correctly) added TLS 1.2 support that integration worked once again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 02:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3210027#M905439</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-03T02:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security manager Integration with Cisco ISE for Security group Tag resolution</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3700250#M905442</link>
      <description>&lt;P&gt;CSCvg18306&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3700250#M905442</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2018-09-04T10:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security manager Integration with Cisco ISE for Security group Tag resolution</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3700255#M905445</link>
      <description>&lt;P&gt;Thanks for providing the BugID&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285490"&gt;@Peter Koltl&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/3700255#M905445</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-04T10:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security manager Integration with Cisco ISE for Security gro</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/4442070#M1082629</link>
      <description>&lt;P&gt;Gents&lt;/P&gt;&lt;P&gt;i have similar problem with CSM 4.19 &amp;amp; ISE 2.1.&lt;/P&gt;&lt;P&gt;i took capture &amp;amp; found ISE talks to CSM with TLS1.2 but it always finish with session setup failure after Test button submission&lt;/P&gt;&lt;P&gt;i cant access bug id. so what is the pill to heal it?&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 18:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/4442070#M1082629</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-08-01T18:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security manager Integration with Cisco ISE for Security gro</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/4442699#M1082646</link>
      <description>&lt;P&gt;selfresolved. A&amp;amp;UG for CSM 4.20:&lt;/P&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;ISE Version&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;Beginning with version 4.18, Cisco Security Manager supports integration of only ISE version 2.3.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 02 Aug 2021 07:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-integration-with-cisco-ise-for-security/m-p/4442699#M1082646</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-08-02T07:50:39Z</dc:date>
    </item>
  </channel>
</rss>

