05-27-2021 01:58 AM
Hi Guys,
I just want to double confirm my understanding for this feature ISE acts as a pxGrid Controller and FMC subscribes to the controller to receive session data. Note: we have a normal install of ISE not ISE PIC... (Not actually used or installed that before looks like a different install altogether.)
To use pxGrid we need to have plus licensing per user?
We are also going to need all users wired/wireless/vpn that are using passive identity/user based rules on the FW to avoid issues.
Thanks
05-27-2021 02:07 AM
Yes, you'll need plus licensing (in addition to base) to use pxgrid services. Once settings up the pxgrid connection will send ip/user (and sgt if using trustsec) mappings to the FMC, which in turn will send on to the FTDs.
05-30-2021 06:03 AM
I think the licensing statement is incorrect. If you have a Base License you are allowed to run pxGRID for Cisco Subscribers only
To quote the configuration guide:
License Package: Base
Passive identity services available as part of the upgrade from ISE-PIC to a Base license include limited pxGrid features available to Cisco subscribers only.
05-30-2021 07:13 AM - edited 05-30-2021 07:15 AM
I believe the "limited pxGrid features" alludes to the fact that you get only user-IP mapping for Cisco subscribers such as FMC.Not the full context data that ISE can potentially share via the higher license tiers ("Plus" under ISE 2.x or "Advantage" under 3.x smart licenses).
Basically it's the same as what you get from ISE-PIC (which is just a stripped down ISE deployment that only collects that basic data).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide