cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Can FMC integrate to more than one ISE deployment ?

Arne Bier
VIP Advisor VIP Advisor
VIP Advisor

Hello

 

Just checking whether it would be possible to have the FMC integrated to another standalone ISE node (acting as its own  PAN/MnT/pxGrid)

 

I think the answer is 'no' since I had a look on my own FMC and even though I can specify two pxGrid nodes, I assumed that both of those pxGrid nodes would have to be in the same ISE deployment (cluster/ISEcube).

 

While on that subject, for SD-Access purposes, is there ever any direct FTD integration with ISE/pxGrid, or is this always handled by FMC<->ISE integration? 

 

regards

2 ACCEPTED SOLUTIONS

Accepted Solutions

Mohammed al Baqari
VIP Advisor VIP Advisor
VIP Advisor
All FMC versions can integrate with single PxGrid deployment. Having that
said, with FMC pre-6.7 the answer is no cuz they use pxGridv1. However with
the introduction of PxGrid v2 in FMC, you can have single integration with
one ISE deployment. Additionally, you can run python scripts on FMC for
additional subscribers to other ISE nodes using PxGridv2.

Here are some sample scripts on how to use PxGrid Python Subscribers.

https://github.com/cisco-pxgrid/pxgrid-rest-ws/tree/master/python

***** please remember to rate useful posts

View solution in original post

@Arne Bier 

If your FTD is not managed by FMC, then you can add an ISE identity source directly from the on-box Firepower Device Manager.

If the FTD is managed by CDO, it will be aware of an ISE integration added from FDM (but we cannot currently configure the integration directly from CDO).

View solution in original post

5 REPLIES 5

Mohammed al Baqari
VIP Advisor VIP Advisor
VIP Advisor
All FMC versions can integrate with single PxGrid deployment. Having that
said, with FMC pre-6.7 the answer is no cuz they use pxGridv1. However with
the introduction of PxGrid v2 in FMC, you can have single integration with
one ISE deployment. Additionally, you can run python scripts on FMC for
additional subscribers to other ISE nodes using PxGridv2.

Here are some sample scripts on how to use PxGrid Python Subscribers.

https://github.com/cisco-pxgrid/pxgrid-rest-ws/tree/master/python

***** please remember to rate useful posts

oh last question @Mohammed al Baqari  - is there a direct integration between FTD and ISE ? Or is it only ever FMC and ISE?

You can run any machine as PxGrid client. I did this on Mac and CentOS. I
don't know if the level of permissions on FTD expert mode with sudo allows
that. Give it a try. As long as you have the permissions and python
installed you should be fine

***** please remember to rate useful posts

@Arne Bier 

If your FTD is not managed by FMC, then you can add an ISE identity source directly from the on-box Firepower Device Manager.

If the FTD is managed by CDO, it will be aware of an ISE integration added from FDM (but we cannot currently configure the integration directly from CDO).

Mohammad, can you manually add multiple ISE deployment via PXGrid v2 or is that only possible using phython script?

 

Thx Khalid

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: