cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2401
Views
0
Helpful
2
Replies

ISE PIC and Firepower Integration

danhamil
Cisco Employee
Cisco Employee

Team,

If ISE PIC is configured to only receive identity information via syslogs.

If I configure ISE PIC to send these syslog learned identity information to the Firepower Management Center, will the FMC be able to create policies based on these identities?

Or can the FMC only create user based policies based on ISE PIC identities learned from AD via WMI or ISE PIC AD agent?

Thanks,

-Dan

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

FMC can only consume Passive Identity learned from AD. The method should not matter,  for the integration to work, the following is what is required currently.

  1. On the FMC, a Realm is configured for the Active Directory with domain and other information.
  2. The session received from ISE-PIC/ISE  should have a domain that the realm domain configured on the FMC.
  3. The session received from ISE-PIC/ISE should have a username that is one of the users in the Active Directory Realm.

LDAP and other sources are in our future roadmap.

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

I forwarded your inquiry to the teams.

hslai
Cisco Employee
Cisco Employee

FMC can only consume Passive Identity learned from AD. The method should not matter,  for the integration to work, the following is what is required currently.

  1. On the FMC, a Realm is configured for the Active Directory with domain and other information.
  2. The session received from ISE-PIC/ISE  should have a domain that the realm domain configured on the FMC.
  3. The session received from ISE-PIC/ISE should have a username that is one of the users in the Active Directory Realm.

LDAP and other sources are in our future roadmap.