08-20-2018 08:59 AM
Hi,
I have an upcoming PoC with a customer and they asked me today, during install, whether or not (and if yes how) integrates with Cisco ISE (does it?).
I do not know much about ISE beyond the 2min "commercial" I watched on the Cisco homepage just there.
I have signed up for a webinar on ISE but since that doesnt take place too soon I would like to know what I can tell our customer.
If someone could explain, in a nutshell, how ISE works, what it does and how it could be integrated with NSO (if possible) I would be very grateful (links with further info highly appreciated).
Or is it possibly something that doesnt make sense at all? If so, why?
:( ...I could NOT find anything on ISE integration with NSO here: https://community.cisco.com/t5/security-documents/ise-design-amp-integration-guides/ta-p/3621164
Solved! Go to Solution.
08-20-2018 09:13 AM
Hi,
You should ask your customer what they want to achieve from this integration.
If it is simple external authentication, this is supported today.
If it is a closer policy integration, I believe the BU is exploring how to get this done but it would also be possible with some work.
Roque
08-21-2018 02:07 AM
I want to expand on Roque's answer slightly, and hopefully @frjansso can chime in too since he has worked with ISE.
ISE handles identity, so that is keeping track of which users should belong to which group and which policies to assign between groups. It is meant as a backend for 802.1X or similar.
There is an ISE NED that is used for this integration. We support a few different things including setting policies. But as Roque says, ask your customer what they want and it is likely it could be doable if the REST interface supports it.
08-20-2018 09:13 AM
Hi,
You should ask your customer what they want to achieve from this integration.
If it is simple external authentication, this is supported today.
If it is a closer policy integration, I believe the BU is exploring how to get this done but it would also be possible with some work.
Roque
08-20-2018 09:24 AM
08-20-2018 10:35 AM
Thanks again for the reply.
I just searched the docs and found that there is some info on external authentication in the admin guide, chapter 9.
I will read up on how to configure it.
P.S.: Sorry for not checking the docs first before posting here...was simply easier to write a quick post via my phone as I was in the middle of cooking dinner and making sure my little daughter doesnt watch too much TV.
08-21-2018 02:07 AM
I want to expand on Roque's answer slightly, and hopefully @frjansso can chime in too since he has worked with ISE.
ISE handles identity, so that is keeping track of which users should belong to which group and which policies to assign between groups. It is meant as a backend for 802.1X or similar.
There is an ISE NED that is used for this integration. We support a few different things including setting policies. But as Roque says, ask your customer what they want and it is likely it could be doable if the REST interface supports it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide