cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2551
Views
0
Helpful
3
Replies

Common problems on endpoints with Cisco ise

sumanth2464
Level 1
Level 1

Hi There,

we are going to roll out Cisco ISE in our organization, 

so i would like to know 10 common issues -- when Cisco ISE is on network, what are the most common problems that comes on end points. need only on end point perspective.

Can any one help me to know the issues. Thanks.

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Volumes have been written on these issues. A lot depends on your ISE High Level Design. That would scope the potential issues by defining the following (off the top of my head):

Are you doing wired, wireless and VPN?

What client types will you be needing to support?

Are you using native 802.1x supplicants or using Cisco AnyConnect?

Do you manage your endpoints already? What about moble endpoints of those are in scope?

Do you have an existing Certificate Authority or PKI setup?

Are you allowing self-service provisioning (a la BYOD) and/or guest self-registration?

Will you be requiring machine authentication?

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

Volumes have been written on these issues. A lot depends on your ISE High Level Design. That would scope the potential issues by defining the following (off the top of my head):

Are you doing wired, wireless and VPN?

What client types will you be needing to support?

Are you using native 802.1x supplicants or using Cisco AnyConnect?

Do you manage your endpoints already? What about moble endpoints of those are in scope?

Do you have an existing Certificate Authority or PKI setup?

Are you allowing self-service provisioning (a la BYOD) and/or guest self-registration?

Will you be requiring machine authentication?

sumanth2464
Level 1
Level 1

Hi Marvin,

please check the briefly description to your questions,   

Are you doing wired, wireless and VPN?

Yes, we are doing wired, wireless and vpn.

What client types will you be needing to support?

We are supporting  windows 7 & 10  client, 

Are you using native 802.1x supplicants or using Cisco AnyConnect?

we are Cisco AnyConnect 4.2 ver.

Do you manage your endpoints already? What about moble endpoints of those are in scope?

yes, we need managing mobile endpoints .

Do you have an existing Certificate Authority or PKI setup?

yes we have existing CA setup.

Are you allowing self-service provisioning (a la BYOD) and/or guest self-registration?

we are doing guest sponsored portal, here we need to do guest validation too. please suggest the available option(1 or more) for guest validation.

Will you be requiring machine authentication?

Yes, we require machine authentication.

OK. Since you asked specifically about endpoints, I would say the biggest issue is user awareness. When you intorduce ISE it changes how user endpoints access the network. If it is not communicated well and thoroughly, it can result in many issues even when all the technical aspects are done correctly. For that reason, Cisco recommends doing a phased implementation starting in monitor-only mode and working through to a clsoed mode implementaiton gradually.

As far as technical issues, the most common ones are the wide variety of endpoints. For your managed endpoints you can control and deploy exactly the software you want. For your mobile endpoints, ISE can integrate with your Enterprose Mobility Management (EMM) solution via API to check for device status (requires Apex license level).

However since you are allowing guest and BYOD, that introduces unmanaged endpoints. You have no control over what OS, software, etc. the users will have there and need to realize that the clients will "misbehave" and sometimes produce unexpected results.

For your guests, a lot depends on what access you will give them. For instance, you can require nothing other than sponsor approval to give guest internet only access. If you are allowing authorized guests internal network access, you may want to check their posture (Apex license required) and ensure that they have a current antivirus product. Or you may want to limit their internal access only to specified resources. Some organizations I have worked with require a valid phone number and enforce that by sending the guest credentials via SMS only. Others do the same with an email. 

There are some good Cisco Live presentations about these topics - definitely review them at www.ciscolive365.com

Review Cisco Networking for a $25 gift card