How To's - Deploy Cisco Identity Services Engine (ISE) 2.7

How To's - Deploy Cisco Identity Services Engine (ISE) 2.7

Hi there, in this post we’re going to deploy Cisco Identity Services Engine (ISE) version 2.7, on VMWare Workstation and make it join a domain controller.

There are some pre-requirements that I recommend you should have in your environment before deploying ISE. They are not mandatory as per Cisco requirements but I had some issues by adding them at a later stage, like the NTP on ISE wouldn’t sync correctly with the NTP Server and to fix it you have to log into the root level and use a tool to help you troubleshoot the problem… short story, just add it at the installation phase. These are the requirements:

  • Ensure the gateway is reachable
  • Ensure the DNS Server is reachable
  • Ensure the NTP Server is reachable

To deploy a DNS Server, check my post How To's - Deploy Windows Server 2019 as a Domain Controller and DNS Server.

https://www.dhirubhai.net/pulse/how-tos-deploy-windows-server-2019-domain-dns-sil%C3%A9sio-carvalho/

Now let’s begin by downloading ISE ova file from Cisco Software Download page: https://software.cisco.com/download/home

To download ISE you don’t need a contract associated with your account.

No alt text provided for this image

At the time of this writing, the recommended version is 2.7, it means this is considered the most stable release.

Once we have the image, we’ll import it on VMWare Workstation > Open a Virtual Machine > Select the image.

No alt text provided for this image

Specify the location where the image will be stored and set a name for easier reference.

Press Next in Deployment Options > Eval > Import

Once the importing finishes you may see an upgrade option for ISE VM. Upgrade the machine to the latest Hardware compatibility option and choose Alter this virtual machine in the end.

No alt text provided for this image

By default ISE comes pre-configured with some values for CPU, memory, hard disk and interfaces. If your host can afford it just keep them by default, in my case I changed them to lower values.

No alt text provided for this image

Press ok and power on ISE.

In login prompt just type setup (don’t try to login, like I did once :-)

No alt text provided for this image

Next provide the required values for ISE (hostname, IP address...).

No alt text provided for this image

Be patient because this process my last for a while (more than 30 mins). Once it completes successfully, we’ll have to wait some more couple of minutes to let the applications start.

You can verify the application status by typing the command show application status ise.

No alt text provided for this image

Once the STATE column show running for most of the applications on the top side, then we can access the web page.

No alt text provided for this image

The username and the password is the same as the console credentials.

No alt text provided for this image

Once you login you’ll be presented with a page requesting your Cisco Account ID, you may skip this step by choosing the option Provide later.

No alt text provided for this image

Then it will show you a page describing your license evaluation period, just accept and close.

No alt text provided for this image

At this stage, we have successfully deployed ISE 2.7. Now let’s join an AD Server.

In the menu bar, select Work Centers > Ext ID Sources 

No alt text provided for this image

Then go to External Identity Sources > Active Directory > Add >

In Join Point Name set the name that will represent the AD Server in ISE.

In Active Directory Domain field, type the domain name.

No alt text provided for this image

After submitting this connection it will ask us if we want to join ISE with the Active Directory Domain. Press Yes.

No alt text provided for this image

Next provide a user with admin privilege in AD.

No alt text provided for this image
No alt text provided for this image

If the operation status is successful, we can then add specific groups from AD that will be used to authenticate and authorize users on per group filtering.

No alt text provided for this image

And we have successfully deployed ISE 2.7 and make it join an active directory.

I’ll write another article, showing you how to provide network access for users using ISE.

I hope you enjoyed this post, leave your comments below and I'll see you on the next one.


Reference:

https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/install_guide/b_ise_InstallationGuide24/b_ise_InstallationGuide24_chapter_011.html#cpp_n2s_rdb


You great, bro!

回复

要查看或添加评论,请登录

Silésio Carvalho的更多文章

  • The Power of Visualization

    The Power of Visualization

    I am Silésio Carvalho, CCIE #65745 and I passed the CCIE lab exam on November 30 2021. If you paid attention to the…

    8 条评论
  • ForticlientEMS fails connection with Fortihate

    ForticlientEMS fails connection with Fortihate

    For those trying to play with Fortigate ZTNA, if you're using Fortigate on evaluation mode, one of the restrictions…

  • Why you won't become a CCIE

    Why you won't become a CCIE

    I'm not the author for the text below but I wanted to share this with you, in case you're thinking about taking the…

    10 条评论
  • Trobleshoot SD-WAN – Part 2

    Trobleshoot SD-WAN – Part 2

    Hi there, in the last article we saw how to troubleshoot control connection failure on Cisco SD-WAN, caused by…

  • Trobleshoot SD-WAN – Part 1

    Trobleshoot SD-WAN – Part 1

    Hi there, While deploying Cisco SD-WAN you might face control connection errors related to certificate. Here are some…

  • Como eu come?aria de novo, em Networking (Redes)?

    Como eu come?aria de novo, em Networking (Redes)?

    Estou nesta jornada a mais de uma década e até a data, tem sido uma caminhada nada fácil (por op??o minha) mas muito…

    6 条评论
  • CCIE - The Plan

    CCIE - The Plan

    Hi there, first of all, I’d like thank everyone for the congratulations messages. As a thank you back, I’ll share with…

    20 条评论
  • How To's - Deploy Checkpoint Remote Access VPN

    How To's - Deploy Checkpoint Remote Access VPN

    Hi there, in this post we'll see how to deploy remote access using Checkpoint Remote Access VPN client. Some…

    3 条评论
  • How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    Hi there, in this post we're going to deploy DMVPN Front Door VRF and using ansible. Basically, we'll be using DMVPN…

    1 条评论
  • How To’s – Deploy DMVPN Dual Hub Dual Cloud

    How To’s – Deploy DMVPN Dual Hub Dual Cloud

    Hi there, in this post we’ll see how to deploy DMVPN Dual Hub Dual Cloud. Basically it means we’ll have two or more…

社区洞察

其他会员也浏览了