Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Subordinate CA comes in picture, when you have PKI wherein certificates are being issued to the end-points from subordinate. In order to support Distributed ISE deployment you have to create certificates with SAN. Please refer following link- http:...
SNMP trap is not available, however you can configure logging, please refer following link, http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/configuration/guide/swlog.html#wp1103706
Please refer the steps given in following given link, in order to configure Cisco ISE IPEP in bridge mode. http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_ipep_deploy.html
Yes this is possible by Configuring the Identity Firewall, please refer following link- http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_idfw.html
You might have mistakenly enabled probes on ISE node and also configured required probes settings on WLC. Disable enabled probes and remove configured settings from WLC. Your problem would get resolved.