04-17-2019 08:21 AM
Hi All,
I am looking to implement IDFW on the network using Cisco ASA 55xx NG appliances. I understand the Context Directory Agent is not supported on ESXi 5.5 upwards and also potential support issues with Windows 2012 too. Looking at the download section it seems the CDA has not had any development since 2014. My question is;
1. What is the alternative to CDA to provide IDFW on the ASA-55xx NG's - ISE/ISE-PICS?
2. If ISE/ISE-PICS - can someone provide me some documents around it as I cannot find anything in relation to ASA 55xx NG's
Thanks in advance!
Mo
Solved! Go to Solution.
04-17-2019 12:36 PM
IDFW on ASA still requires CDA. There has been a recent patch for CDA published to support up to Windows 2016. ISE / ISE-PIC does not currently support the sharing of identity information to ASA as it lacks the CDA RADIUS interface it requires.
Regards,
-Tim
04-17-2019 12:36 PM
IDFW on ASA still requires CDA. There has been a recent patch for CDA published to support up to Windows 2016. ISE / ISE-PIC does not currently support the sharing of identity information to ASA as it lacks the CDA RADIUS interface it requires.
Regards,
-Tim
04-18-2019 03:42 AM
04-18-2019 03:43 AM
But the CDW is not maintained any longer and has not been for a good 3-4 years..
Additionally, CDA is not supported on ESXi 5.0 and above and I believe there are support issues with Windows 2012/2016.
I had raised a TAC case too and they have confirmed ISE can do IDFW with ASA 55xx?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide