cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
849
Views
0
Helpful
1
Replies

Passive-ID identity sharing and pxgrid Licensing

bilclay
Cisco Employee
Cisco Employee

Sourced from partner: Is there a way to share the passive ID info via pxGrid to Cisco devices but not the active authentications? Having both active and passive would be great, but we have many customers using ISE who will never purchase enough plus licensing to make it compliant. I realize they could run a second ISE deployment as ISE-PIC, but that would probably be more expensive than the plus licenses in most cases.

 

In ISE 2.4 you can set up permissions for pxGrid clients.   I was thinking that you could possibly use this to only provide the passive info to clients, but as far as I can tell, it’s all session info or none.

Thanks!

1 Reply 1

hslai
Cisco Employee
Cisco Employee

Duplicate of ISE Passive-ID identity sharing and pxg...

Regarding licensing, base only applies to Cisco subscribers. Still needs 1:1 plus to base for non-Cisco subscribers.

I am not aware a way to subscribe selectively between active and passive auth sessions. However, the SDK has subnet filters. For example, How to use Data Exchange Layer with Cisco Platform Exchange Grid (pxGrid) shows,

Field Description
pxGrid Hosts Enter the host name or IP address for the pxGrid controllers that the DXL brokers connect to.
Client Name Prefix This field identifies the name of the client connection from the DXL brokers to the pxGrid fabric in the Cisco ISE console. You can change this name, and it is updated in the pxGrid user interface.
Client Description This field identifies the description of the client connection from the DXL brokers to the pxGrid fabric in the Cisco ISE console. You can change this description, and it is updated in the pxGrid user interface.
Client Groups Specifies the group capabilities for which the DXL brokers bridging to Cisco pxGrid are requesting access. If you do not want a capability to be available via the bridge between DXL and Cisco pxGrid, click the minus icon to remove it. To enter a new capability, click the plus icon.
Certificate Password The password used to create the certificate in Cisco ISE for use with DXL.
Notifications Notifications are received via the pxGrid fabric. Select the types of notifications to bridge from the pxGrid fabric to DXL.
Session Notification Subnet Filter Receive session notifications from specific subnets. Leave this field empty to receive session notifications for all subnets, or enter a comma-separated subnet address to receive notifications only from those subnets. For example:

1.0.0.0/255.0.0.0,1234::/16