05-11-2017 07:09 PM
Hi Team,
I understand that we have a list of ecosystem partner for pxGrid and PAN is not listed there. Do we have any case study or any partner for reference who has done the ISE integration with PAN for Rapid Threat Containment…or any document which talks about the integration of Cisco ISE with Palo Alto Firewall for RTC.
Though I could find a link (http://www.cisco.com/c/en/us/products/security/pxgrid.html ) where it mention “With pxGrid, any connected technology can instruct the Cisco Identity Services Engine (ISE) to contain a threat," but was not able to find the some specific information related to Palo Alto Firewall. Any caveats???
Solved! Go to Solution.
05-12-2017 10:38 AM
Anshul,
We haven't tested PAN with ISE for RTC. My understanding is the integration is limited to ISE sending syslog information for PAN to ingest. Unfortunately, we don't have any documentation that covers how to set this up.
Regards,
-Tim
10-01-2018 03:44 AM
10-02-2018 04:43 AM
05-12-2017 10:38 AM
Anshul,
We haven't tested PAN with ISE for RTC. My understanding is the integration is limited to ISE sending syslog information for PAN to ingest. Unfortunately, we don't have any documentation that covers how to set this up.
Regards,
-Tim
11-15-2017 08:13 AM
Can ISE BU test this PAN with ISE integration ASAP and publish some example documentation? This will certainly help partners to position ISE for all identity related management.
I have a customer who use PAN for URL filtering. They enable PAN SSL Decryption for URL Filtering. All Group membership are out of active directory. They're trying to fetch group data via SAML on ADFS. PAN can only use LDAP for Group mapping for User-Identification.
Can we position ISE pxGrid to make this user-id mapping work for PAN URL filtering?
11-15-2017 08:20 AM
Again as hslai stated please reach out to ISE product management team thru the sales channel with your use case.
05-12-2017 10:38 AM
There is no current support. Please discuss your use cases with our product management teams.
10-01-2018 12:44 AM
Hi all,
Any update about posibility of having PAN "talking" to our ISE via PxGRID?
I have customer who concerns this issue.
Rgds,
Minh
10-01-2018 03:44 AM
10-01-2018 11:36 PM
Thanks for your advice.
Asking PaloAlto SE, I got the following answer:
- PA FW could use PxGRID to send to ISE quarantine request
- PA FW could get the user information from ISE indirectly with the help of a free tool MineMeld + PxGRID
Minh
10-02-2018 04:43 AM
04-12-2019 01:20 AM
Hi Everyone,
I have the same problem with the Fortigate FW. Does anyone know how to integrate Fortigate FW with the Cisco ISE for RTC?
Thanks
Waqas
04-12-2019 05:33 AM
12-18-2019 10:18 PM
03-27-2020 03:35 AM - edited 03-27-2020 03:37 AM
Hi Guys,
I have read a lot of articles about Palo Alto Cisco ISE and now I understand that I can do this through MineMeld.
A pxgrid configuration is required on the Cisco ISE side.
I will prepare a document of interest soon.
04-01-2021 11:30 AM
Emre did you ever get around to doing a Document which covered this?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide