02-18-2014 07:00 AM - edited 03-10-2019 09:25 PM
I have a new ISE box and want to use AD for management. I have ISE successfully connected to AD and can authenticate to the management interface using AD. My next step is to filter specific users from the AD group for authentication. Is this possible? If so, any help or documents would be greatly appreciated.
Thanks in advance.
Bret
Solved! Go to Solution.
02-18-2014 07:14 AM
Yes, you can use specific AD groups and apply ISE poilcy.
http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1059262
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
__________________________________________________
"Im like bacon, I make your wireless better"
02-18-2014 08:11 AM
I would recommend creating a new active directory group called "ISE Admins" or something and assigning that group to the ISE Admin group inside of ISE you created based on step 4 in my instructions above.
02-18-2014 07:14 AM
Yes, you can use specific AD groups and apply ISE poilcy.
http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1059262
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
__________________________________________________
"Im like bacon, I make your wireless better"
02-18-2014 07:23 AM
You're done!
02-18-2014 07:57 AM
Thank you both for a quick response. I have ISE joined to AD and can authenticate without any problem. Since the AD group I am using has several users I need to filter specific users out for ISE management. I am very new to ISE and from what I have read and what you mention George I need to create a policy filtering out the users. Is that correct?
02-18-2014 08:11 AM
I would recommend creating a new active directory group called "ISE Admins" or something and assigning that group to the ISE Admin group inside of ISE you created based on step 4 in my instructions above.
02-19-2014 05:05 AM
Allthough ISE can do the policy, for someone new to ISE I found it a little challenging, so I used an AD group. Thank you both for the quick response.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide