cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1780
Views
0
Helpful
2
Replies

ISE and Firepower Identity : update interval for Active Directory and other identity sources

giovanni.augusto
Beginner
Beginner

Hi Everyone,

 

I know that ISE can provide user-to-ip mappings to FMC and based on that user access control can be enforced (and with rapid threat containment as well).

 

What I would like to know is how often the user-to-ip mappings are updated? I used to run some test with Firesight AD agent and I recall there were a regular interval to update the mappings and that was not feasible for our production environment, using ISE makes it realtime since it uses WMI or is it still bound to scheduled updates ?

 

Thank you

2 Accepted Solutions

Accepted Solutions

Mohammed al Baqari
VIP Advisor VIP Advisor
VIP Advisor
With ISE it uses PxGRID which is based XMPP subscription. FMC will
subscribe to ISE PixGrid and after that it will be push from ISE to FMC
instead of poll from FMC to ISE. This means that you don't have regular
interval based sync. Instead its based on changes detected by ISE will be
notified to FMC

*** Remember to rate useful posts

View solution in original post

Mohammed is correct. It uses PxGrid for Adaptive Network Control to take action. FMC consumes session directory and Trustsec meta data to gather user, IP, SGT information etc.
Essentially it uses PxGrid 1.0 based on XMPP and rest as mentioned above.

View solution in original post

2 Replies 2

Mohammed al Baqari
VIP Advisor VIP Advisor
VIP Advisor
With ISE it uses PxGRID which is based XMPP subscription. FMC will
subscribe to ISE PixGrid and after that it will be push from ISE to FMC
instead of poll from FMC to ISE. This means that you don't have regular
interval based sync. Instead its based on changes detected by ISE will be
notified to FMC

*** Remember to rate useful posts

Mohammed is correct. It uses PxGrid for Adaptive Network Control to take action. FMC consumes session directory and Trustsec meta data to gather user, IP, SGT information etc.
Essentially it uses PxGrid 1.0 based on XMPP and rest as mentioned above.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers