Cisco ISE

Overview

Cisco ISE is something that I have worked on at multiple organisations. ISE is a very clever product that can simplify the management of a network for user ports. Essentially it removes the traditional VLAN/user type being tied to a physical switch port. ISE allows you to define a type of user based on their AD attributes. ISE can then push physical switchports configuration based off the user attributes. This could be as simple as a VLAN or more complex things such as; ACLs permitting different access based on username or scanning a laptop to determine if it has the correct software of Windows security updates.

In this project I will create an ISE topology and build out different features in ISE as a demonstration of the capabilities it has. By no means will this be a comprehensive look at all the ISE features. Instead it will concentrate on the core features that the majority of organisations will find useful and what I have seen in my previous experience.

The lab that I have used for this is a couple of years old. I created it in conjunction with Checkpoint to see traffic flows, VPNs and firewall rules. Most of this will be concentrating on the lower half of the topology. However as the project progresses most of the network devices will be used.

Arista
Using ISE AAA TACACS For Arista XMPP
In the previous XMPP post, I was using local users in the XMPP ejabberd server. There was command...
index
ISE Lab: API 4 - Search for Endpoint
This post will find the details of an endpoint off the MAC address, and then see all the endpoints...
index
ISE Lab: API 3 - Create & Delete dACLs
This will be creating and deleting a dACL. Again, details can be found in the built-in ISE...
index
ISE Lab: API 2 - First API GET Requests with Postman
Now that the API has been configured, it can be tested. In this post, I will show a few base...
partner-logo-cisco-ise
ISE Lab: API 1 - Setup
ISE does not have the REST API enabled by default. It must be enabled in the ISE admin tab. When...
partner-logo-cisco-ise
ISE Lab: Wired 3 - 802.1x Posture
The posture configuration is very similar to the one that was created in the Anyconnect VPN...
partner-logo-cisco-ise
ISE Lab: Wired 2 - 802.1x Configuration
This is the first time I have managed to make this work in a GNS3 environment in several years...
partner-logo-cisco-ise
ISE Lab: ASA AnyConnect 2 - ISE Posture
The ISE posture scanning will work on wired, wireless and VPNs. There are multiple steps to...
partner-logo-cisco-ise
ISE Lab: ASA AnyConnect 1 - VPN, RADIUS and Policy Sets
This lab is demonstrating the use of Cisco AnyConnect and ISE. AnyConnect can be used in conjunction...
partner-logo-cisco-ise
ISE Lab: Wired 1 - RADIUS & Switch RADIUS Config
This is the configuration to get the switch access-switch1 to talk to ISE. This is the beginning...
partner-logo-cisco-ise
ISE Lab: Backup & Restore ISE
As this is a lab topology, it relies on lab licenses. For ISE this means that there is a 90...