05-11-2018 08:47 AM - edited 02-21-2020 10:55 AM
Dears,
i have a FMC and ISE in my network and i m planning to configure the threat containment , i don't have any internal CA , and planning to do with self signed CA of each others (FMC and ISE standalone) will it work ???
OR
CA server is must for integration.
Thanks
Solved! Go to Solution.
05-11-2018 10:22 AM
Hi, The server/client EKU basically indicate what the purposes the certificate can be used for.
If you have ISE 2.2 then this will be fine.
This document describes the steps, it's based on ISE 2.2
HTH
05-11-2018 10:05 AM
Hi,
It's important that the certificate used for pxgrid integration has server and client authentication EKU. If you use ISE 2.2+, you can use it's internal CA to sign the certificate used for the FMC.
HTH
05-11-2018 10:14 AM
Dear
i would like thank u for reply.
can u elaborate more for client server authentication eku means ????
i m using 2.2 patch 7 i dont have any internal ca. If I build ise 2.2 patch 7 as a ca server will it work ???? or compulsory to have above 2.2 to build ise as a ca server.
so u r confirming that default signed certificates will not work.
thanks
05-11-2018 10:22 AM
Hi, The server/client EKU basically indicate what the purposes the certificate can be used for.
If you have ISE 2.2 then this will be fine.
This document describes the steps, it's based on ISE 2.2
HTH
05-11-2018 11:36 PM
05-12-2018 01:08 AM
Hi,
Yes, you need the ISE pxgrid integration with FMC in order to quarantine the users. Configuring the pxgrid with ISE and FMC shouldn't cause any downtime, it's up to you if you implement in a change window. Implementing this is only on the FMC not the FP sensor.
HTH
05-12-2018 01:17 AM
Please find the attached snapshot, as per the docs provided by u on pg 22
it is showing to use a Identity service engine instead of user agent, so if i move to ISE them all user to ip mapping will be provided by ISE, becz FMC will stop communicating with user agent and will start with ISE,
I have four cisco documents which are making me confuse to setup the pxgrid. i don't know which to follow:
Thanks
05-15-2018 12:18 PM
05-15-2018 12:27 PM
You will need to use pxgrid integration with ISE in order to quarantine (Threat Containment), the FMC User Agent won't allow you to do that.
This video might help in setting up integration
05-19-2018 07:20 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: