Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

I am attempting to get the Profiler FeedService working in our ISE (2.4, Patch 9) deployment, but it keeps returning a non-helpful "null" error whenever I test it:Test result: Failure: FeedService test connection failed : Feed Service error : null **...

joe_lizzi by Level 1
  • 1855 Views
  • 4 replies
  • 0 Helpful votes

Hi,   My customer wants to integrate ISE with ForeScout so the products can play well together. The question they are asking is what does ForeScout need to do in order to talk to pxGrid. What API’s does ForeScout have to create on their product in or...

syedah2 by Cisco Employee
  • 5566 Views
  • 2 replies
  • 0 Helpful votes

Customer use case:   We were able to retrieve certificates from our Microsoft Certificate Authority to our ChromeOS devices.  This satisfies one of the conditions to permit a Chrome OS device to access our Cisco ISE wifi access point.   However, we n...

lkaripis by Cisco Employee
  • 1244 Views
  • 1 replies
  • 0 Helpful votes

I have some devices that are hitting my default (open) rule that I want to hit an earlier rule. The problem is that I am not getting enough attributes from them until I have the profile perform an NMAP scan. But the device has already performed auth ...

Hey guys, Wanting to know if there is anyway in the Dacl syntaxto get host range /24 to work we have a range of hosts, 135 of them that every time we add a new server we have to update the Dacl.what i would like to do is something like this to keep i...

songley by Level 1
  • 541 Views
  • 1 replies
  • 0 Helpful votes

With current configuration setup for ISE and ID-PSK, using Cisco AV Pairs in the Authorization profile to hold the network key - these attributes in the Authorization profile are shown in clear text in the Live log details. The ISE Live Logs are acce...

I have created sub-policy to Microsoft-Workstation that looks for the same attributes, but adds in DHCP host-name. The devices are still getting profiled as Microsoft-Workstation instead of 'SJ-Desktop' even though they clearly meet the host-name cri...

1.PNG 2.PNG 3.PNG

Resolved! PSN Limits

Hello, I am looking at some of the ISE designs and had a question around the following design. If I run two PAN/MnT nodes but run primary PAN/secondary MnT on Node 1 and Primary MnT/secondary PAN on Node 2 is there still a limit of 5 PSNs in this dep...