cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1051
Views
0
Helpful
6
Replies

ISE integration with Third Party Proxy

ecanogut
Cisco Employee
Cisco Employee

Hello all,

One of my customer wants to integrate ISE with a Fortinet proxy so that when a user (already authenticated on ISE) wants to navigate on internet the proxy does not prompt for user's credentials.

My understanding is ISE should send authorization session to the proxy to achieve this.

Does any one has done something similar to this?.

Thanks in advanced.

1 Accepted Solution

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee

This functionality is already supported by Cisco WSA.  The WSA uses pxGrid to fetch SGT information for the end user accessing the internet.  Fortinet would need to build a pxGrid client into their solution to download identity information from ISE.

Regards,

-Tim

View solution in original post

6 Replies 6

Timothy Abbott
Cisco Employee
Cisco Employee

This functionality is already supported by Cisco WSA.  The WSA uses pxGrid to fetch SGT information for the end user accessing the internet.  Fortinet would need to build a pxGrid client into their solution to download identity information from ISE.

Regards,

-Tim

Jason Kunst
Cisco Employee
Cisco Employee

please see several other posts on the issue with ISE sending RADIUS to Fortinet

https://communities.cisco.com/search.jspa?q=ise+fortinet

ecanogut
Cisco Employee
Cisco Employee

So, my question is: Can fortinet be integrated with ISE using PxGrid?

Have you asked fortinet if they have a PXGrid client in any of their firewalls?

Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.

No, you will need to ask them to reach out and start the process

https://www.cisco.com/c/en/us/products/security/pxgrid.html

Thank you all for your answers, will inform the customer about it.