01-09-2019 03:04 AM
Hi, we are trying to get our Cisco ISE to integrate with the Checkpoint Identity Collector but have encountered an issue in that the smart collector will only ever see the Cisco ISE PSN node as 'Disconnected'.
There appears to be well documented guides for deploying the checkpoint identity collector with Active Directory and with ISE from the checkpoint side but no guides out there for configuring it from the Cisco ISE side.
Any help would be much appreciated.
Solved! Go to Solution.
01-09-2019 02:07 PM
Hi,
It appears that you have a certificate issue between Checkpoint & the ISE pxGrid node.
How do you have ISE deployed and which version are you using? If you are just using the ISE internal CA with 2.2, please see: https://community.cisco.com/t5/security-documents/using-ise-2-2-internal-certificate-authority-ca-to-deploy/ta-p/3639747, if you are using an external CA server, please see :https://community.cisco.com/t5/security-documents/deploying-certificates-with-cisco-pxgrid-using-an-external/ta-p/3639677, if you are deploying pxGrid in an ISE productional environment, please see:https://community.cisco.com/t5/security-documents/how-to-configure-pxgrid-in-ise-production-environments/ta-p/3646330
Also ensure that you have your ISE pxGrid published nodes appear and you are in a connected state, (you will see this in the lower left hand corner.
If you have additional questions, please email me directly.
Thanks,
John
jeppich@cisco.com
01-09-2019 01:14 PM
I have asked our sme @jeppich
01-09-2019 02:07 PM
Hi,
It appears that you have a certificate issue between Checkpoint & the ISE pxGrid node.
How do you have ISE deployed and which version are you using? If you are just using the ISE internal CA with 2.2, please see: https://community.cisco.com/t5/security-documents/using-ise-2-2-internal-certificate-authority-ca-to-deploy/ta-p/3639747, if you are using an external CA server, please see :https://community.cisco.com/t5/security-documents/deploying-certificates-with-cisco-pxgrid-using-an-external/ta-p/3639677, if you are deploying pxGrid in an ISE productional environment, please see:https://community.cisco.com/t5/security-documents/how-to-configure-pxgrid-in-ise-production-environments/ta-p/3646330
Also ensure that you have your ISE pxGrid published nodes appear and you are in a connected state, (you will see this in the lower left hand corner.
If you have additional questions, please email me directly.
Thanks,
John
jeppich@cisco.com
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide