02-10-2020 10:02 PM
Hello.,
with regards to Cisco ISE, if in setup and configure the same in my HQ office, will i be able to extend and enforce all policies and profiling details, configured on my HQ appliance, to my branch offices who are connected to HQ over IPSec S2S VPN.
FYI...i have not yet configured ISE on my network, its a new setup.
My BOQ consists of ISE VM small, Base+Apex+Plus+AnyConnect Term Licenses.
Appreciate your feedback in advance.
many thanks
SV
Solved! Go to Solution.
02-10-2020 10:45 PM
02-10-2020 10:45 PM
02-10-2020 10:57 PM
Hello Damien
Thank you for the response.
Basically all services are provided to branch offices from HQ
Branch office only consist of endpoint connected to access switches and from access switch to ASA - IPsec s2s - to HQ
branch offices also have access points in them but are configured on H-REAP mode (FlexConnect) registered to HQ-WLC
And i have HA for the ISE VM appliances, made sure i had that.
That was FYI just so that you are aware of the entire setup
So if i am right, my branch office do not need a separate appliance or any specific licensing to achieve both posturing and profiling policies configured on the the HQ ISE appliance.
best regards
SV
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide