cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7231
Views
6
Helpful
13
Replies

PAN & ISE for Rapid Threat Containment

ankaushi
Cisco Employee
Cisco Employee

Hi Team,

I understand that we have a list of ecosystem partner for pxGrid and PAN is not listed there. Do we have any case study or any partner for reference who has done the ISE integration with PAN for Rapid Threat Containment…or any document which talks about the integration of Cisco ISE with Palo Alto Firewall for RTC.

Though I could find a link (http://www.cisco.com/c/en/us/products/security/pxgrid.html ) where it mention “With pxGrid, any connected technology can instruct the Cisco Identity Services Engine (ISE) to contain a threat," but was not able to find the some specific information related to Palo Alto Firewall. Any caveats???

3 Accepted Solutions

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee

Anshul,

We haven't tested PAN with ISE for RTC.  My understanding is the integration is limited to ISE sending syslog information for PAN to ingest.  Unfortunately, we don't have any documentation that covers how to set this up.

Regards,

-Tim

View solution in original post

Recommend you ask PAN (assume you mean Palo Alto networks?) it’s up to them to integrate

View solution in original post

>From our integration explorers. there is no current integration, please reach out to PAN to adopt Open pxGrid.

View solution in original post

13 Replies 13

Timothy Abbott
Cisco Employee
Cisco Employee

Anshul,

We haven't tested PAN with ISE for RTC.  My understanding is the integration is limited to ISE sending syslog information for PAN to ingest.  Unfortunately, we don't have any documentation that covers how to set this up.

Regards,

-Tim

Can ISE BU test this PAN with ISE integration ASAP and publish some example documentation? This will certainly help partners to position ISE for all identity related management.  

I have a customer who use PAN for URL filtering. They enable PAN SSL Decryption for URL Filtering. All Group membership are out of active directory. They're trying to fetch group data via SAML on ADFS. PAN can only use LDAP for Group mapping for User-Identification.

Can we position ISE pxGrid to make this user-id mapping work for PAN URL filtering?

Again as hslai stated please reach out to ISE product management team thru the sales channel with your use case.

hslai
Cisco Employee
Cisco Employee

There is no current support. Please discuss your use cases with our product management teams.

tminh
Cisco Employee
Cisco Employee

Hi all,

 

Any update about posibility of having PAN "talking" to our ISE via PxGRID?

I have customer who concerns this issue.

 

Rgds,

Minh

 

Recommend you ask PAN (assume you mean Palo Alto networks?) it’s up to them to integrate

Thanks for your advice.

Asking PaloAlto SE, I got the following answer:

- PA FW could use PxGRID to send to ISE quarantine request

- PA FW could get the user information from ISE indirectly with the help of a free tool MineMeld + PxGRID

 

Minh

>From our integration explorers. there is no current integration, please reach out to PAN to adopt Open pxGrid.

waqas1
Level 1
Level 1

Hi Everyone,

 

I have the same problem with the Fortigate FW. Does anyone know how to integrate Fortigate FW with the Cisco ISE for RTC?

Thanks

Waqas

Same guidance, if not listed under http://cs.co/ise-guides then we likely don’t have integration. You would need to have customer request feature from vendor to integrate with our product, it’s open platform sdk

https://developer.cisco.com/site/pxgrid/

Panorama Plugin for Cisco TrustSec....

 

Maybe in the near future we could get Rapid Threat Containment working! Was a dream thought before with PA but looking like reality soon!

Emre Ozel
Level 1
Level 1

Hi Guys,
I have read a lot of articles about Palo Alto Cisco ISE and now I understand that I can do this through MineMeld.
A pxgrid configuration is required on the Cisco ISE side.
I will prepare a document of interest soon.
MineMeld.png

 

Emre did you ever get around to doing a Document which covered this?