Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

Hi,I have a large implementation of ISE in a distributed model with 2 ISEs for PAN and 2 for MnT and centralized PSNs in multiple regions which will cover a lot of branches.unfortunately we can't afford a load balancers behind PSNs and we have to con...

john5 by Level 1
  • 2011 Views
  • 2 replies
  • 0 Helpful votes

Dear All,             One of our customers wants to enable 2 factor authentication for SSH access to their network devices. Currently they have Cisco ISE (ACS-licensed) for device administration(TACACS+). Cisco ISE is integrated with LDAP. Customer w...

I am starting to play around with SMB information more for profiling.  When I scan my domain joined machines I am not getting the domain information:SMB.cpe cpe:/o:microsoft:windows_10::-SMB.lanmanager Windows 10 Enterprise 6.3SMB.operating-system Wi...

paul by Level 10
  • 1372 Views
  • 5 replies
  • 1 Helpful votes

Hello, I'm looking for a deep dive on valid DACL config.Specifically, what is the 'addrgroup' syntax used for? I can type something like:permit ip any addrgroup my_addrgroupin the DACL Content box, and it checks as valid config.If I just enter "permi...

Hello,my customer has a distributed deployment with ISE 2.3P2 - all ISE roles are running on a 3595.2x PAN2x MnT8x PSNPAN and MnT are in the same DC.We have 4916 total endpoints and 4127 active endpoints (as of today).We are seeing gui slowness on sp...

csavas by Cisco Employee
  • 1103 Views
  • 3 replies
  • 0 Helpful votes

Hi team,I am supporting our End-user on the requested feature below:- They deployed ISE at DC and DR, each site has 03 virtual instances (PAN + PSN + MnT).- They have many branches.- The question is: can ISE support each branch only to add/edit/delet...

hanguye3 by Cisco Employee
  • 684 Views
  • 6 replies
  • 1 Helpful votes

For ISE reporting - is it possible to generate reports on devices that tried to connect to the network, but failed authorisation? Also, is it possible to report on how many devices have specific vulnerabilities, based on passive scanning or checks fr...

Team,can you tell me if we have a website or link of all the smartcard vendors we support?  Further question...My customer is  moving to Smart Card authentication.  Which vendors do we support?  Please describe your ability to use Smart Cards on your...

jvanagas by Cisco Employee
  • 1271 Views
  • 1 replies
  • 1 Helpful votes