cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2635
Views
0
Helpful
1
Replies

ISE SGT with Firepower

yongwli
Cisco Employee
Cisco Employee

Hi Experts,

Customer's access switches are HPE switches, they want Firepower to use ISE attribute in ACP, is it possible?

I guess we can define SGT in authorization policy, and switch don't have to support SGT, ISE will send SGT-IP mapping to Firepower. Am I right?

Thanks

DL

1 Reply 1

hslai
Cisco Employee
Cisco Employee

FMC 6.0 can subscribe to ISE via pxGrid for TrustSecMetaData in addition to SessionDirectory and EndpointProfileMetaData, and then use SGT in its access control rules. See How To: Integrate Firepower Management Center (FMC) 6.0 with ISE and TrustSec through pxGrid