01-13-2025 03:16 PM
Are there any benefits to implementing ISE within Catalyst Center if you aren't using SDAccess? We are doing 802.1x wired/wireless but not we are not using SGTs. Just trying to understand how ISE will fit in with Catalyst Center in this deployment.
01-13-2025 03:49 PM
Without SDA I dont see any reason to integrate ISE to DNAC. Actually, even for SGT you dont need ISE/DNAC integration, ISE can do it on its own.
01-13-2025 04:01 PM
There was a discussion on this not too long ago with some detail that might help you:
01-13-2025 06:22 PM
ISE is really good with contextual data, Catalyst Center can display contextual information about users, devices, their authentication/authorization states and profile information from ISE. So I would still recommend to integrate ISE, it does not do you any harm.
01-13-2025 11:05 PM
As I am sure is mentioned in the post @Preston Chilcote linked above. The main benefits of integrating without SDA is that devices are automatically registered when onboarded through PNP and that you can use the "ISE" option under design > network settings.
01-27-2025 02:55 AM
It's also possible to use the device attributes that are passed from Cat C to ISE to create some custom policies. For instance if Cat C indentifies an iPhone for instance you can create a policy that prevents that device from authenticating to a network that you do not want it on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide