cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3016
Views
10
Helpful
3
Replies

pxGrid Integration between ISE and Firepower

Scott_22
Level 1
Level 1

We are working to implement the pxGrid integration between ISE and Firepower. If SGTs and user groups are imported from ISE and used in an ACP, what happens to that policy on the firepower device if the FMC goes down? Please provide documentation describing the result if possible. 

1 Accepted Solution

Accepted Solutions

I could not find a document to prove this what you requested. however, I have tested this in my lab. PxGrid is configured between ISE and FMC. Once FMC learn the SXP information from the ISE PxGrid. I push my policy to FTD. Than later i power off my FMC. therefore as excepted the FTD learn its policy from the FMC therefore the policy remain intact in FTD local database. prior to power off my FMC i took a sniping tool of my result. I set a rule Employees ping to Google must be denied. and the employee SGT number is 4. 900.PNG

 

now FMC is power off if you jump/login to FTD and give command show access-control-config

901.PNG

please do not forget to rate.

View solution in original post

3 Replies 3

I could not find a document to prove this what you requested. however, I have tested this in my lab. PxGrid is configured between ISE and FMC. Once FMC learn the SXP information from the ISE PxGrid. I push my policy to FTD. Than later i power off my FMC. therefore as excepted the FTD learn its policy from the FMC therefore the policy remain intact in FTD local database. prior to power off my FMC i took a sniping tool of my result. I set a rule Employees ping to Google must be denied. and the employee SGT number is 4. 900.PNG

 

now FMC is power off if you jump/login to FTD and give command show access-control-config

901.PNG

please do not forget to rate.

Ah! Great. I don't think there is documentation so hopefully this will help others with the same question. The FTD does maintain policy with ISE attributes once it has been pushed, even if the FMC fails. 

Yes that correct. this is what i tested and posted my results. hope it will help you.

please do not forget to rate.
Review Cisco Networking for a $25 gift card