cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1486
Views
21
Helpful
2
Replies

DNA Center using Forescout

craneman1
Level 1
Level 1

My customer uses Forescout for comply-to-connect.

98 Per cent of DNA deployments use ISE Radius.

Has anyone done Forescout integration using Pxgrid with ISE?

Does this actually work with DNA Center?.

Thanks

2 Accepted Solutions

Accepted Solutions

Hello,

 

  I dont have experience with Forescout but I have experience with DNAC and ISE deployment. As per the docs, the Forescout integrates with ISE via PXGrid and not with DNAC directly. I did not find any doc in which DNAC integrate with Forescout directly, although both speaks PXgrid.

 I attached this document made by cisco about this subject.

 

 

View solution in original post

jedolphi
Cisco Employee
Cisco Employee

Hi Craneman. yes, I worked with FS (Forescout) representatives to successfully pxG integrate FS to ISE and prove that FS can trigger ISE to change context of endpoints (SGT change, SGACL change, etc.) via pxG. This was tested in a POC (proof of concept) lab for a design opportunity that never advanced to production for unrelated reasons (politics, pandemic, etc.). This POC was conducted in July 2020. I'm not able to make firm promises on behalf of FS, but from what I have seen it does work. There might be specific dependencies on the FS side I cannot comment on (code versions, supported/unsupported configurations, etc.) and someone would have to follow up with FS for the specific details/requirements of your design.  Probably the best way forward is for you to speak to your Cisco SE or AM who can engage the appropriate Cisco-internal resources - please have them contact me. Regards, Jerome

View solution in original post

2 Replies 2

Hello,

 

  I dont have experience with Forescout but I have experience with DNAC and ISE deployment. As per the docs, the Forescout integrates with ISE via PXGrid and not with DNAC directly. I did not find any doc in which DNAC integrate with Forescout directly, although both speaks PXgrid.

 I attached this document made by cisco about this subject.

 

 

jedolphi
Cisco Employee
Cisco Employee

Hi Craneman. yes, I worked with FS (Forescout) representatives to successfully pxG integrate FS to ISE and prove that FS can trigger ISE to change context of endpoints (SGT change, SGACL change, etc.) via pxG. This was tested in a POC (proof of concept) lab for a design opportunity that never advanced to production for unrelated reasons (politics, pandemic, etc.). This POC was conducted in July 2020. I'm not able to make firm promises on behalf of FS, but from what I have seen it does work. There might be specific dependencies on the FS side I cannot comment on (code versions, supported/unsupported configurations, etc.) and someone would have to follow up with FS for the specific details/requirements of your design.  Probably the best way forward is for you to speak to your Cisco SE or AM who can engage the appropriate Cisco-internal resources - please have them contact me. Regards, Jerome