ISE Slides
ISE Slides
ISE Slides
2
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Foundations of Zero Trust in Your Workplace
Grant the right level of Shrink zones of trust and Automate containment of
network access to users grant access based on infected endpoints and
across domains least privilege revoke network access
3
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ISE Provides Zero Trust for the Workplace
Enterprise Security
ISE
Cisco DNA Center
4
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ISE Secure Access Control Options
Native Supplicants | Cisco AnyConnect SAML IdPs Single Sign-On
Up to 100K Certificate
Network Devices Authorities External Identity Stores
SCEP/CRL
Azure Active Directory
WebAuth
Enterprise LDAP/SQL Active Directory
Network OAuth:ROPC
VPN
ISE SQL Server
Built-in CA
5
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Why Customers Buy ISE
TACACS+ Migrating from Cisco Secure ACS or building a new Device Administration Policy Server, this
Device Administration allows for secure, identity-based access to the network devices
Allow wired, wireless, or VPN access to network resources based upon the identity of the
Secure Access user and/or endpoint. Use RADIUS with 802.1X, MAB, Easy Connect, or Passive ID
Differentiate between Corporate and Guest users and devices. Choose from Hotspot, Self-Registered
Guest Access Guest, and Sponsored Guest access options
Use the probes in ISE and Cisco network devices to classify endpoints and authorize them
Asset Visibility appropriately with Device Profiling. Automate access for many different IoT devices
Group-based Policy allows for segmentation of the network through the use of Scalable Group Tags
Segmentation (SGT) and Scalable Group ACLs (SGACL) instead of VLAN/ACL segmentation.
ISE integrates with DNA Center to automate the network fabric and enforces the policies throughout the
Cisco SDA/DNAC entire network infrastructure using Software-Defined Access (SDA)
Allow employees to use their own devices to access network resources by registering their device and
BYOD downloading certificates for authentication through a simple onboarding process
Using a Threat Analysis tool, such as Cisco Cognitive Threat Analytics, to grade an endpoints threat
Threat Containment score and allow network access based upon the results
6
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Device Administration with TACACS+
Network Admin
7
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
A Typical Customer Journey
Not a standard or recommended approach
Each use case may be the end goal
Use Case
Visibility Visibility
Customer Corporate
Start with Secure Wired See Apps & Use SGTs for Integrate with
Wireless Access HW inventory segmentation eco-system
partners
Non-disruptive 802.1X / MAB Enforce system Enforce Group
due to SSIDs (with Profiling) compliance based policies Contain threats
BYOD
8
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Guest Solution Overview
1
million API
9
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ISE BYOD Solution
Public
Device Support EMM/MDM Integrations
Android
Resources
✕✓✕✓✓✓
Devices
macOS ✓✓✕✓✕✕
✕✓✓✕✕✕
Windows
Corporate
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential https://cisco.com/go/csta 10
Endpoint Profiling
The profiling service in Cisco ISE identifies the devices that connect to your network
AnyConnect: ACIDex
Endpoints send
interesting data,
that reveal their
device type Feed Service
(Online/Offline)
DS ISE
ACIDex
11
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Profiling Packages and Integrations
Medical Devices IOT Building & Automation
Library
X pX s1
250+ Medical
Hospital device profiles
pxGrid ISE
IND
Factory
Cisco Industrial
Network Director Cisco AI Endpoint Analytics
Industrial Devices
Profiles IOT devices and sends endpoint labels via pxGrid to ISE for authorization
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential https://community.cisco.com/t5/tag/ise-endpoint-profile/tg-p/board-id/4561-docs-security12
Cisco AI Endpoint Analytics and ISE
Cisco ISE
Web Interface Cisco DNAC+EA
Context
Classifications ISE
Policy
Endpoint Analytics shows
device classification results
associated with endpoints Distribution
SPAN
Layer
Wireless LAN
NBAR Telemetry Traffic Controller
(SD-AVC Agent) Appliance (TTA)
Catalyst 9000
13
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Group Based Policy Simplifies Segmentation
Traditional Segmentation TrustSec DC Servers
Non-Compliant Voice Employee Supplier BYOD Voice Non-Compliant Employee Supplier BYOD
14
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Non-Fabric Group-Based Policy Enforcement
deny icmp
deny udp src dst eq domain
deny tcp src dst eq 3389
deny tcp src dst eq 1433
deny tcp src dst eq 1521
deny tcp src dst eq 445
deny tcp src dst eq 137
deny tcp src dst eq 138
deny tcp src dst eq 139
deny udp src dst eq snmp
deny tcp src dst eq telnet
15
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Context Build, Summarize, Exchange
Visibility and Access Control Context Reuse
ISE builds context and applies access control restrictions to users and devices by eco-system partners for analysis & control
Scalable Group
Endpoints
16
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Posture & Compliance MDM Attributes
ActivityType
AdminAction
AdminActionUUID
AnyConnectVersion
DaysSinceLastCheckin
DetailedInfo
DeviceID
DeviceName
DeviceType
DiskEncryption
Agentless EndPointMatchedProfile
FailureReason
IdentityGroup
IMEI
Authorization Policy IpAddress
JailBroken
AnyConnect IF JailBroken is No LastCheckInTimeStamp
Posture
Umbrella Module
HostScan (aka: ASA posture) (No UI)
Network Visibility Module (NVM) (No UI)
18
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Agentless Posture 3.0
Employee
802.1X / MAB
Compliant
Unknown
PowerShell / SSH
Posture Status
19
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Threat Visibility Rapid Threat Containment (RTC)
1 2 AMP on Endpoint notifies the cloud
Jim 5
3
Threat from
Harry Jim’s device
Cisco ISE
Alice
20
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Vulnerability Assessment (Threat-Centric NAC)
On-prem Scanner
3 Scans Scan report 4
Jim 1 6
2 Scan Jim’s Endpoint
5
CVSS=10
Harry
Cisco ISE
Alice
Authorization Policy
If CVSS is Greater than 5 = true, then Quarantine
CVSS: Common Vulnerability Scoring System
21
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ISE REST APIs
http://cs.co/ise-api
22
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ISE Architecture
Distributed ISE
Standalone ISE Policy Administration Node (PAN)
• Single plane of glass for ISE admin
• Replication hub for all config changes
pxGrid Controller
• Facilitates sharing of context
23
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential http://cs.co/ise-scale
ISE Node Personas… Explained
SIEM, MDM, NBA, IPS,
IPAM, etc.
ISE PSN IP address* =
Admin
ANC action PAN
AAA RADIUS server SIEM
Context (pxGrid)
Operates
ISE-PXG
Authorization Policy Exchange Topics
*PSNs can optionally be behind a load-balancer and can be accessed via Load Balancer Virtual IP address (VIPs)
24
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
• Resources
ISE Customer http://cs.co/ise-resources
Resources • Community
http://cs.co/ise-community
• YouTube Channel
http://cs.co/ise-videos
• Evaluations
http://cs.co/ise-eval
• Integration Guides
http://cs.co/ise-guides
• Compatibility Guides
http://cs.co/ise-compatibility
• Licensing Guide
http://cs.co/ise-licensing
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential