cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1658
Views
0
Helpful
5
Replies

Catalyst Center and ISE integration

Todd S
Level 1
Level 1

Are there any benefits to implementing ISE within Catalyst Center if you aren't using SDAccess?  We are doing 802.1x wired/wireless but not we are not using SGTs.  Just trying to understand how ISE will fit in with Catalyst Center in this deployment.

5 Replies 5

@Todd S 

 Without SDA I dont see any reason to integrate ISE to DNAC. Actually, even for SGT you dont need ISE/DNAC integration, ISE can do it on its own. 

Preston Chilcote
Cisco Employee
Cisco Employee

There was a discussion on this not too long ago with some detail that might help you:

https://community.cisco.com/t5/cisco-catalyst-center/dnac-catc-and-ise-what-does-dnac-do-and-what-do-you-have-to-do/td-p/5240015

 

ammahend
VIP Alumni
VIP Alumni

ISE is really good with contextual data, Catalyst Center can display contextual information about users, devices, their authentication/authorization states and profile information from ISE. So I would still recommend to integrate ISE, it does not do you any harm.

-hope this helps-

Torbjørn
VIP
VIP

As I am sure is mentioned in the post @Preston Chilcote  linked above. The main benefits of integrating without SDA is that devices are automatically registered when onboarded through PNP and that you can use the "ISE" option under design > network settings.

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

Olu802-11
Cisco Employee
Cisco Employee

It's also possible to use the device attributes that are passed from Cat C to ISE to create some custom policies. For instance if Cat C indentifies an iPhone for instance you can create a policy that prevents that device from authenticating to a network that you do not want it on.