Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other troubleshooting best practices.

Labels

Forum Posts

Hello, we deploy a Cisco ISE dot1.x solution with two 2960 (WS-C2960X-48FPD-L(15.2(2)E7 ) & WS-C2960-24PC-L(15.0(2)SE11)) both switches work fine with our scenario with no problem  but a few weeks ago the WS-C2960X cant run IP device tracking so we c...

vergil by Level 1
  • 681 Views
  • 0 replies
  • 0 Helpful votes

Hi,I have a large implementation of ISE in a distributed model with 2 ISEs for PAN and 2 for MnT and centralized PSNs in multiple regions which will cover a lot of branches.unfortunately we can't afford a load balancers behind PSNs and we have to con...

john5 by Level 1
  • 2094 Views
  • 2 replies
  • 0 Helpful votes

Dear All,             One of our customers wants to enable 2 factor authentication for SSH access to their network devices. Currently they have Cisco ISE (ACS-licensed) for device administration(TACACS+). Cisco ISE is integrated with LDAP. Customer w...

I am starting to play around with SMB information more for profiling.  When I scan my domain joined machines I am not getting the domain information:SMB.cpe cpe:/o:microsoft:windows_10::-SMB.lanmanager Windows 10 Enterprise 6.3SMB.operating-system Wi...

paul by Level 10
  • 1536 Views
  • 5 replies
  • 1 Helpful votes

Hello, I'm looking for a deep dive on valid DACL config.Specifically, what is the 'addrgroup' syntax used for? I can type something like:permit ip any addrgroup my_addrgroupin the DACL Content box, and it checks as valid config.If I just enter "permi...

Hello,my customer has a distributed deployment with ISE 2.3P2 - all ISE roles are running on a 3595.2x PAN2x MnT8x PSNPAN and MnT are in the same DC.We have 4916 total endpoints and 4127 active endpoints (as of today).We are seeing gui slowness on sp...

csavas by Cisco Employee
  • 1171 Views
  • 3 replies
  • 0 Helpful votes

Hi team,I am supporting our End-user on the requested feature below:- They deployed ISE at DC and DR, each site has 03 virtual instances (PAN + PSN + MnT).- They have many branches.- The question is: can ISE support each branch only to add/edit/delet...

hanguye3 by Cisco Employee
  • 796 Views
  • 6 replies
  • 1 Helpful votes

For ISE reporting - is it possible to generate reports on devices that tried to connect to the network, but failed authorisation? Also, is it possible to report on how many devices have specific vulnerabilities, based on passive scanning or checks fr...