cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
367
Views
1
Helpful
1
Replies

IT & OT Collaboration / Convergence

aavnet89
Level 1
Level 1

Hello, Cisco Community!

Connected Plant-wide Ethernet Architecture (Industry 4.0), as referenced, suggests that Identity Services (ISE) should be held at Level 3 (Site Operations) of the design, with Enterprise based Identity Services remaining outside of IDMZ, isolated within Enterprise space. Is there a use case, where Identity Services are shared? Assuming that Identity deployment can be optimised and fashioned in a way that endpoints / supplicants are able to support Microsoft PKI (as an example). Or would as the design suggests, keep identity services separate in most scenarios?

Thanks in advance.

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

Since no reference was provided, I found the Cisco Validated Designs for Digital Manufacturing > Industrial Automation design guide > Cell/Area Zone Ring Topologies with the image Figure 13 Industrial Automation Network Model and IACS Reference Architecture showing the AAA/ISE server in Industrial Zone Level 3 :
    

image.png

> Is there a use case, where Identity Services are shared?

Definitely. Many customers like to have a centralized policy for simplicity when all managing all access control scenarios  across manufacturing and other corporate sites, organizations, departments, etc.

> endpoints / supplicants are able to support Microsoft PKI

"Microsoft PKI" is a generic term and I don't know if this means Active Directory or Azure or something else. You can see "Domain Controller" sitting next to ISE which would be your AD so ... Yes.

View solution in original post

1 Reply 1

thomas
Cisco Employee
Cisco Employee

Since no reference was provided, I found the Cisco Validated Designs for Digital Manufacturing > Industrial Automation design guide > Cell/Area Zone Ring Topologies with the image Figure 13 Industrial Automation Network Model and IACS Reference Architecture showing the AAA/ISE server in Industrial Zone Level 3 :
    

image.png

> Is there a use case, where Identity Services are shared?

Definitely. Many customers like to have a centralized policy for simplicity when all managing all access control scenarios  across manufacturing and other corporate sites, organizations, departments, etc.

> endpoints / supplicants are able to support Microsoft PKI

"Microsoft PKI" is a generic term and I don't know if this means Active Directory or Azure or something else. You can see "Domain Controller" sitting next to ISE which would be your AD so ... Yes.