cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
708
Views
2
Helpful
2
Replies

Cisco ISE Multiple Sites

Leonardo Santana
Spotlight
Spotlight

Hi how can i make policy sets with Cisco ISE for multiple sites?

I just want to use 802.1x for wired and wireless network.

 Its better to create a policy set to each site?

Example:
SITE A (Headquarter)
SITE B (Branch 1)
SITE C (Branch 2)
SITE D (Branch 3)

Regards
Leonardo Santana

*** Rate All Helpful Responses***
2 Accepted Solutions

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

The only reason to do that would be if you need to provide different authorization on a per-site basis, which would not scale well and would be an operational burden. Ideally, you would create a centralised policy that would apply to all sites.

I would suggest reviewing the Cisco ISE Secure Wired Access Prescriptive Deployment Guide for example policies.

If you're new to ISE, there are also various Webinars available to gain a better understanding of the features and best practices.
https://cs.co/ise-resources#Learn

 

View solution in original post

thomas
Cisco Employee
Cisco Employee

Only create different policy sets if your policies are indeed different otherwise, keep your life and policies simple and use the same everywhere! You typically want to create different policy sets for different access methods (wired, wireless, VPN) or authentication types (MAB, 802.1X) or scenarios (Corporate, IOT, Guest) or locations (country, region, zone, etc.) or any combinations of these as needed.

See ISE Authentication and Authorization Policy ReferencePolicy Set Conditions

We also had an ISE webinar  Building ISE RADIUS Policy Sets 2022/05/03

and another one on ▷ Managing Network Devices in ISE 2022/04/05 :

19:10 RADIUS with an Undefined Network Device
21:08 Enable and Use the Default Network Device
24:43 Network Device with an IP Range
26:30 Network Device with a Specific IP Address
28:00 Packet Capture Review
31:46 Network Device Groups (NDGs)
34:12 CSV Export & Import of NDGs and Network Devices

View solution in original post

2 Replies 2

Greg Gibbs
Cisco Employee
Cisco Employee

The only reason to do that would be if you need to provide different authorization on a per-site basis, which would not scale well and would be an operational burden. Ideally, you would create a centralised policy that would apply to all sites.

I would suggest reviewing the Cisco ISE Secure Wired Access Prescriptive Deployment Guide for example policies.

If you're new to ISE, there are also various Webinars available to gain a better understanding of the features and best practices.
https://cs.co/ise-resources#Learn

 

thomas
Cisco Employee
Cisco Employee

Only create different policy sets if your policies are indeed different otherwise, keep your life and policies simple and use the same everywhere! You typically want to create different policy sets for different access methods (wired, wireless, VPN) or authentication types (MAB, 802.1X) or scenarios (Corporate, IOT, Guest) or locations (country, region, zone, etc.) or any combinations of these as needed.

See ISE Authentication and Authorization Policy ReferencePolicy Set Conditions

We also had an ISE webinar  Building ISE RADIUS Policy Sets 2022/05/03

and another one on ▷ Managing Network Devices in ISE 2022/04/05 :

19:10 RADIUS with an Undefined Network Device
21:08 Enable and Use the Default Network Device
24:43 Network Device with an IP Range
26:30 Network Device with a Specific IP Address
28:00 Packet Capture Review
31:46 Network Device Groups (NDGs)
34:12 CSV Export & Import of NDGs and Network Devices