09-11-2013 01:51 PM - edited 03-04-2019 09:00 PM
Hello everyone.
I have such situation. I got specification for new project from last engineer who quit. And there is such system as Cisco ISE. I dont know what is it( And now my boss wants to know do we need to buy it or can we just setup our new network without it. Can any explain shorty what is it and can we set our network without it.
Solved! Go to Solution.
09-12-2013 05:57 AM
Depends on how secure you want your network.
For example it can be used to prevent unauthorised users from plugging their laptop into a data outlet and getting a valid IP. They can launch DDOS attacks or sniff packets etc etc.
Can also check the virus signature file on a PC. If it is not update it will put that PC is a quarantine VLAN and upgrade the software. Once completed it will then allow the PC to connect to the network.
09-11-2013 02:14 PM
What is the exact part number ?
09-12-2013 05:01 AM
ISE-3315-K9
09-12-2013 05:57 AM
Depends on how secure you want your network.
For example it can be used to prevent unauthorised users from plugging their laptop into a data outlet and getting a valid IP. They can launch DDOS attacks or sniff packets etc etc.
Can also check the virus signature file on a PC. If it is not update it will put that PC is a quarantine VLAN and upgrade the software. Once completed it will then allow the PC to connect to the network.
10-10-2013 08:56 PM
Hi Volodymyr,
Cisco Identity Services Engine (Cisco ISE) is a next-generation identity and access control policy platform that enables enterprises to enforce compliance, enhance infrastructure security, and streamline their service operations. The unique architecture of Cisco ISE allows enterprises to gather real-time contextual information from networks, users, and devices. The administrator can then use that information to make proactive governance decisions by tying identity to various network elements including access switches, wireless LAN controllers (WLCs), Virtual Private Network (VPN) gateways, and data center switches. Cisco ISE is a key component of the Cisco Security Group Access solution.
Cisco ISE is a consolidated policy-based access control system that incorporates a superset of features available in existing Cisco policy platforms. Cisco ISE performs the following functions:
•Combines authentication, authorization, accounting (AAA), posture, and profiler into one appliance
•Provides for comprehensive guest access management for Cisco ISE administrators, sanctioned sponsor administrators, or both
•Enforces endpoint compliance by providing comprehensive client provisioning measures and assessing the device posture for all endpoints that access the network, including 802.1X environments
•Provides support for discovery, profiling, policy-based placement, and monitoring of endpoint devices on the network
•Enables consistent policy in centralized and distributed deployments that allows services to be delivered where they are needed
•Employs advanced enforcement capabilities including Security Group Access (SGA) through the use of Security Group Tags (SGTs) and Security Group Access Control Lists (SGACLs)
•Supports scalability to support a number of deployment scenarios from small office to large enterprise environments
For further information you can check the below link,
http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_user_guide.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide