cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3211
Views
5
Helpful
11
Replies

Install Tenable agent on Cisco ISE Server

sinady
Level 1
Level 1

Dear Team,

 

Currently my tenable team need to install tenable agent on Cisco ISE server for perform scanning on server level.

 

As Cisco ISE server running on virtual appliance. So it is OK to install tenable agent on ISE server? 

Does anyone experience on this ?

 

Really appreciate for your advise.

1 Accepted Solution

Accepted Solutions

I'm not aware of a public document that specifically states that, but the User Roles and Permissions for Monitoring and Troubleshooting Capabilities section of the Admin Guide does include a note that states:

Accessing Cisco ISE using the root shell without Cisco TAC supervision is not supported, and Cisco is not responsible for any service disruption that might be caused as a result.

 

View solution in original post

11 Replies 11

Mike.Cifelli
VIP Alumni
VIP Alumni

As Cisco ISE server running on virtual appliance. So it is OK to install tenable agent on ISE server? 

-Not feasible.

Thank @Mike.Cifelli for your feedback. It mean Cisco doesn't allow to install any software on ISE server? Did you have any reference document based on this.

Could you help to share on this ? Thank you.

The ISE application and database is built on top of a hardened Red Hat operating system. There is no access to the underlying operating system without a temporary root patch that is provided by TAC solely for troubleshooting. As such, it is not possible/supported to install any additional software packages on the ISE appliance.

Thank you so much @Greg Gibbs , By the way, do you have any reference document from Cisco about this?

Could you help to share it. Please!

I'm not aware of a public document that specifically states that, but the User Roles and Permissions for Monitoring and Troubleshooting Capabilities section of the Admin Guide does include a note that states:

Accessing Cisco ISE using the root shell without Cisco TAC supervision is not supported, and Cisco is not responsible for any service disruption that might be caused as a result.

 

I see and thank you.

Hi, 

Can i install tenable on the PGs and the RGR servers  ?

What are 'PGs' and 'RGR' servers? I don't recognise these acronyms in relation to Cisco ISE.

@Greg Gibbs:  I thought ISE application and database is built on top of CentOS and NOT Red Hat, right?  I am pretty sure I saw the CentOS during the system boot up.  CentOS is very similar to Red Hat but it is not 100% the same.  

No, it's a hardened version of RedHat which is why the installation steps for VMware state to use the Guest OS Version for RHEL rather than CentOS. 

Screenshot 2023-09-01 at 8.04.58 am.png

markbyrne
Level 1
Level 1

its not ISE related, it UCCE - Rogger and Peripheral Gateway