06-09-2018 02:29 PM - edited 02-21-2020 10:57 AM
Dears,
I am really new to trust sec and we have a ISE in a corporate, how I can take benefit of trust sec if I am having ASA-SM as a core datacenter firewall and ASA-5525X on a perimeter firewall and 2960XR switches on the access layer with IP base licenses
I am using following features of ISE which fits to my corporate also trust sec will fit but I don't know how I can design and implement trust sec feature. I can say it is a replacement of CDA ( context directory Agent) or it does much more than CDA ???
Thanks
06-09-2018 02:42 PM - edited 06-09-2018 02:45 PM
Using ISE you can assign a Trustsec TAG (SGT) to each user/computer, this is defined in the authorization policy, and can be assigned depending on AD group membership and/or whether the user passes or fails posture etc. These SGTs can be used in the firewall ruleset to permit/deny access. If you integrate ISE with Firepower using pxgrid you can initiate user quarantine if their computer has malware etc.
This link is the best place to start for TrustSec information
06-10-2018 09:39 PM
@Rob Ingram I don't believe the ASA-SM is on the Trustsec Compatibility Matrix.
06-16-2018 03:42 PM
Dears
Thanks for the reply,
+5 to you both, I will reply further on this post as I have many question on the trust sec.
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide