cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1848
Views
5
Helpful
3
Replies
lekang
Cisco Employee

ISE Identity Mapping for FMC via pxGrid

I'm running ISE 2.0-306 and FMC 6.0.1-1214 which I have the set up in the lab for customer PoV.

Test case 1: User visibility and access control for 802.1x users (PASSED)

- FMC connected to ISE via pxGrid successfully

-  Passive Auth was enabled on FMC

- 802.1x authenticated users information were displayed on FMC connection event table (This shows that pxGrid is working)

- FMC successfully blocked user access based on AD group.

Test case 2: User visibility and access control for non-802.1x users using ID Mapping (FAILED)

- FMC connected to ISE via pxGrid successfully

- -Passive Auth was enabled on FMC

- Users logon to AD (non-802.1x) and I could see an ID Mapping event captured on ISE Radius Live session window.

- However, no user information were displayed on FMC connection event table even though pxGrid was working

- FMC failed to block user access based on AD group.

I read from the user guide that AD login information can be shared by ISE ID Mapping module to FMC (pxGrid subscriber) via pxGrid:

"The Identity Mapping component retrieves the user logins from the Domain Controller and imports them into the Cisco ISE session directory. So users authenticated with Active Directory (AD) are shown in the Cisco ISE live sessions view, and can be queried from the session directory using Cisco pxGrid interface by third-party applications. The known information is the user name, IP address, and the AD DC host name and the AD DC NetBios name. The Cisco ISE plays only a passive role and does not perform the authentication. When Identity Mapping is active, Cisco ISE collects the login information from the AD and includes the data into the session directory.”

A couple of questions here,

1) Are there any command on ISE allow us to check via the User-to-IP mapping table?

2) How do we verify that User-to-IP mapping table on ISE shared with FMC?

3) How frequent FMC pulls from ISE or ISE push session directory information to FMC?

Are we missing anything from configuration wise?

How do we troubleshoot from here?

Regards, CK

1 ACCEPTED SOLUTION

Accepted Solutions
Timothy Abbott
Cisco Employee

Hi,

You can check the session directory on ISE to learn the user to IP mapping.  You can find it by going to the RADIUS Live Long then clicking on Show Live Sessions.  To validate that FMC is able to get information from pxGrid, check pxGrid Services by going to Administration then clicking on pxGrid Services.  Under the clients tab, you should see fsmc-agent-sourcefire3d or similar.  In my lab, FMC is subscribed to EPS and not session but that may be because of the version of FMC I'm running.  You'll have to ask the FMC team on the polling frequency of pxGrid as I'm not sure.  Hope this helps.

Regards,

-Tim

View solution in original post

3 REPLIES 3
Timothy Abbott
Cisco Employee

Hi,

You can check the session directory on ISE to learn the user to IP mapping.  You can find it by going to the RADIUS Live Long then clicking on Show Live Sessions.  To validate that FMC is able to get information from pxGrid, check pxGrid Services by going to Administration then clicking on pxGrid Services.  Under the clients tab, you should see fsmc-agent-sourcefire3d or similar.  In my lab, FMC is subscribed to EPS and not session but that may be because of the version of FMC I'm running.  You'll have to ask the FMC team on the polling frequency of pxGrid as I'm not sure.  Hope this helps.

Regards,

-Tim

View solution in original post

I could see identity mapping was working in Show Live Session window which was good. How do I verify on that ISE indeed sends User-to-IP mapping to FMC via PxGrid?

--

Choo-Kai on mobile

Please excuse spelling and grammar

I would check the logs of the FMC to see when it requests information from ISE.  You can also check the client log under pxGrid Services in ISE.

Regards,

-Tim

Content for Community-Ad