cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7883
Views
5
Helpful
5
Replies

ISE Internal DataBase

gugonza2
Cisco Employee
Cisco Employee

Hi Team,

I have some questions about ISE internal database:

  • What is the database engine of ISE internal databases ?
  • Is the content of ISE database encrypted ?
  • Is it possible to connect to ISE database using a AD domain user ?
  • What controls or functionalities does the solution have to safeguard the integrity and security of the information received, stored, modified and / or processed?

Thanks in advance,

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

See ISE Security Best Practices (Hardening)or more details including some info on DB encryption on FAQ.

There is no direct access the the underlying databases.  Yes, there is more than one.  Access to config is provided via the ISE Admin UI or via ERS API.

View solution in original post

5 Replies 5

dmh
Level 5
Level 5

ISE uses an Oracle database.

The best way to access ISE information remotely is using the REST API interface which also ensures the database integrity.

The database tables and structure would can (and does) change between versions so using an API abstracts this so your code doesn't need to be updated every time this happens.

See the following for the REST API documentation:

Cisco Identity Services Engine API Reference Guide, Release 2.x - Cisco

Craig Hyps
Level 10
Level 10

See ISE Security Best Practices (Hardening)or more details including some info on DB encryption on FAQ.

There is no direct access the the underlying databases.  Yes, there is more than one.  Access to config is provided via the ISE Admin UI or via ERS API.

Thx,  Just a last question;  are these DBs encrypted ?

Any document or references with that information ?

Please refer to the link already provided.  It states that database is not encrypted.  Data fields other than passwords are not encrypted, but ISE admin users do not have direct accesses to the database in normal operations.