cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
1
Helpful
1
Comments
alexiflo
Cisco Employee
Cisco Employee

Introduction

This community article will go through the step-by-step process of how to integrate Catalyst SD-WAN with ISE. This integration enables identity-based firewall rule making on Catalyst Edge devices for micro-segmentation at the branch. 

Prerequisite: ISE Configuration

 

Step 1 -  Configure ISE before Catalyst SD-WAN integration

 
Step 1.1 - Enable PxGrid services.
 
alexiflo_0-1736445408287.png
 
Step 1.2 - Enable password-based account creation. This is required so SD-WAN Manager can make API calls to ISE to create credentials.
 
alexiflo_2-1736445484536.png
 
Step 1.3 - Enable ERS and OpenAPI (enabled by default in ISE 3.4 or later).
 
alexiflo_3-1736445581045.png

 

Step 2 - Add Active Directory as external identity source (Optional)

 

Step 2.1 - Add AD as an external identity source for user/usergroup integration on ISE.

alexiflo_4-1736446309471.png

 
 
Step 2.2 - Select usergroups to be made available for policy configuration.
 
alexiflo_5-1736446412756.png

Step 3 - SGT Integration: Configure SGTs and static IP to SGT mappings on ISE if demo/testing is required (Optional)

 

Step 3.1 - Create additional SGTs and IP-to-SGT static mappings to test identity-based FW rules if needed.
 
alexiflo_6-1736446674248.png
 
Step 3.2 - The SGT to IP mappings will be shared from ISE to Controller through SXP which then would be shared to edge devices within that domain.
 

alexiflo_7-1736447100295.png

 

Step 3.3 - Create SGT domain for every VPN

SXP Domain is a collection of SXP devices, and the administrator can decide which domain to send IP-to-SGT mappings to. Controller will send IP –SGT Mappings to SD-WAN Edge based on what VPNs are associated with that SXP domain.

 

alexiflo_1-1738803017661.png

Create new SGT Domain.

alexiflo_2-1738803301567.png

Repeat for each Service VPN.

alexiflo_3-1738803432100.png

Step 3.4 - Add SD-WAN Controller as new SXP Device.

Add Controller as SXP device to receive updates from new IP-SGT mappings created on ISE

Click 'Add' to add new SXP device.

alexiflo_2-1738858629207.png

 Add SD-WAN Controller information.

alexiflo_14-1738870393011.png

 

 

 Save the configuration.

alexiflo_15-1738870432298.png

Catalyst SD-WAN Manager and ISE integration configuration

 

Step 4 - Configure SD-WAN controller for ISE integration

 
On the Catalyst SD-WAN Manager, attach a device template to the SD-WAN Controller.
 
Step 4.1 - For the VPN0 template, add the static DNS mapping of ISE.
 
alexiflo_16-1738870481199.png

 

Then, push the template to the SD-WAN Controller.

 

alexiflo_1-1738866328542.png

 

Step 4.2 - Add ISE integration on Catalyst SD-WAN Manager
 
Go to Administration > Identity Service Engine. Then click on 'Add Connection'.
 
alexiflo_2-1738866460084.png

 

Add ISE details.

 

alexiflo_17-1738870533936.png

 

Option 1: Select and add User Groups info.

 

alexiflo_4-1738866601972.png

 

Option 2: Select Security Group Tags

 

alexiflo_18-1738870599948.png

Then click 'Submit'.

Once integrated, Catalyst SD-WAN Manager does the rest of the automation such as:

  • Creating client account for PxGrid
  • Adding credentials on SD-WAN controller (vSmart) for ISE connectivity
  • Pulls user/user-group (or SGT) information for security policy creation

alexiflo_19-1738870648823.png

 

Verification

 

Check connection status of ISE integration.

Once ISE integration is complete, refresh the integration page and status should show as ‘Connected’ and ‘In Sync’.

Deleting ISE connection will require that identity-list references in the security policies are deleted first.

 

alexiflo_20-1738870688190.png

View PxGrid status

You can check the PX Grid status by clicking on the three dots under ‘Action’ and select ‘View PX Grid Status’

alexiflo_21-1738870740069.png

Successful integration will show as ‘Connection Successful’

Otherwise, you will see error message such as ‘Connectivity Failed’

alexiflo_9-1738867610996.png

User Groups integration: Check user info learned on Catalyst SD-WAN Manager from ISE

Click on 'View ISE Data'.

alexiflo_22-1738870779943.png

Click on 'Users' tab.

alexiflo_23-1738870823750.png

 

Click on 'User Group' tab.

alexiflo_24-1738870874592.png

SGT integration: Check SGT info learned on Catalyst SD-WAN Manager from ISE

Same process to view SGT data. Click on 'View ISE Data'.

 
alexiflo_25-1738870908687.png
Comments

@alexiflo  thank you for this topic. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: