Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

Is it possible to do group mapping in ISE? I was able to do this in ACS and map an external AD group to an identity group when creating an access policy. Which would allow me to create a single authorization policy that would affect both internal and...

user1024 by Level 1
  • 554 Views
  • 2 replies
  • 0 Helpful votes

Hi,   I am a bit annoyed that ISE doesn't report what is wrong when it is unable to retrieve an AD group.  I have different branches in my AD tree, but ISE is only able to retrieve groups from one of them. For example it can find groups under domain/...

ISE 2.3.0.298 External Sources: AD Mode: Monitor MAR: On (12hrs) Cisco Phones-EAP Switches: Correctly Configured per Interface   Policy:      Authentication:      EAP-TLS - Network Access·EapTunnel Equals TTLS - Use Sequence (Internal Endpoints, AD) ...

Hi Team,   I'm testing to issue certificates for EAP-TLS, and found expiration TTL is always set to 2 years for server cert.   When I configured certificate templates for client cert, I could set 3652 days at maximum.   But when I configured CSR for...

Client-side.png Server-side.png ise.png
masyamad by Cisco Employee
  • 2511 Views
  • 5 replies
  • 0 Helpful votes