cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1890
Views
1
Helpful
12
Replies

ISE / Stealtwatch treat mitigation doesnt work

AndiBuchmann157
Level 1
Level 1

hi,

my ise and stealthwatch are connected  via pxgrid. i followed every step of the " Deploying Cisco Stealthwatch 6.9 with Cisco Identity Services Engine (ISE) 2.2 using Cisco Platform Exchange Grid (pxGrid)" Guide from John Eppich and used the ISE internal CA.

My ISE and Stealthwatch are connected as you can see in the screenshots right here:

Screenshot_1.jpg

Screenshot_2.jpg

Screenshot_3.jpg

Screenshot_4.jpg

Screenshot_5.jpg

Screenshot_6.jpg

thanks in advance!

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

As mentioned in Re: Stealthwatch EPS Integration, the setup has ISE 2.2 Patch 1, which has CSCvc81676, so I suggested to apply Patch 2.

View solution in original post

12 Replies 12

jeppich
Cisco Employee
Cisco Employee

Hey Andreas,

Do you have the aaa server radius dynamic author command configured on your switch?

Thanks,

John

jeppich@cisco.com

Hi John,

thanks for you reply!

Yes, its activated, just doublechecked it

Another point which I am worried about is, I don’t see a IP adress of the host in the live log:

--> see attached image

Would it be helpful for you, if a attach the switch configs?

Thanks in advance and regards,

Andreas

Hey Andreas,

This is most likely a switch configuration issue, please refer to: https://developer.cisco.com/fileMedia/download/63e057cc-beb1-4f66-9836-68d3391f7f0a

Look "Under "802.1X (optional)", you should see the required commands for the switch.  Please check to see if you have these configured on your switch.  More specifically, dhcp snooping, and ip device tracking should be turned on, and you have radius accounting updates configured.

We can also setup a webex, if this still is not working.

Thanks,

John

jeppich@cisco.com

i will check this tomorrow when i am back at the office!

thank you very much for all the effort john!

will get back to you asap!!

I don't believe you need DHCP snooping although it is a security best practice we roll out with ISE typically.  IP device tracking should give you the IP information of the attaching host.

hi guys,

we made a step into the right direction - for now i can see the username and the ip adress, as you can see here:

Screenshot_7.jpg

Screenshot_8.jpg

BUT if i try to put a host in quarantine it says the smc is not connected to the ise, but "obviously" it is:

Screenshot_9.jpg

Screenshot_10.jpg

Thanks and regards,

Andreas

Hey Andreas,

Let's schedule a webex. Email me directly to schedule a webex for next week.  Let me know what days and times work best for you.

Thanks,

John

jeppich@cisco.com

hslai
Cisco Employee
Cisco Employee

As mentioned in Re: Stealthwatch EPS Integration, the setup has ISE 2.2 Patch 1, which has CSCvc81676, so I suggested to apply Patch 2.

i installed patch 2 this morning, but i still can not find any information about the CSCvc81676 - as i already mentioned before..what is that bug about?

done

Did applying patch 2 resolve the issue? The bug is on this issue exactly.

nope it is not. can you provide me any link where i can find more info about that?

i think it is still a little configuration issue, waiting for John's answer atm to schedule a Webex with him