Introduction to Cisco ISE
- Business Benefits of ISE
- ISE Architecture and Components
- ISE Nodes and Personas
- Different ISE Deployment Options
- ISE Licensing Options and Considerations
Provisioning Secure Access
- Authentication Services available with ISE
- Validating Credentials from Different Identity Sources.
- Configuring Authentication Identity Sources and Policies
- ISE Authorization Policies and their Components
- Configuring Authorization Components and Policies
- Define and Understand CoA and review common permission elements, including dACLs, named ACLs, VLANs, and SGT
Configuring Profiling
- Functions and Purpose of Profiling
- Profiler Probes and Attributes associated with these Probes
- Configuring Profiler Policies
- Configuring Profiling
- Verifying Profiler Operation
- Best practices for Configuring Profiling
Providing Guest Access
- Concept of Guest Web Access
- Configuring the Components of a CWA-based Guest Access Solution
- Guest Accounts, Roles, and Data stores
- Functionality of ISE Portals used for Guest Access
- Configuring Support for Guest Reporting
- Best Practices for ISE Guest Services
Implementing BYOD
- Overview of BYOD Components
- Advantages of a BYOD Solution
- Common BYOD Use Cases
- BYOD Deployment and Configuration Options
- BYOD Flow and On-Boarding Process when a Single SSID is used
- Implementing an Authentication Policy for BYOD Deployments
- Implementing an Authorization Policy for BYOD Deployments
Exploring MDM Integration
- MDM Integration Processes
- Adding an MDM Server
- MDM Supported Attributes
- MDM Configuration
Monitoring and Troubleshooting Cisco ISE Security Solutions
- ISE Dashboard
- Navigate ISE Alarm and Logging Features to assist in Diagnosing Problems
- Using the Live Authentications Log feature of Cisco ISE
- Use the Global Search and Session Trace features of Cisco ISE
- Use the TCP Dump feature of Cisco ISE
- Use the Evaluate Configuration Validator tool
Labs
Lab 2-1: Basic Authentication and Authorization
Lab 3-1: Configuring and Validating Cisco ISE Profiling
Lab 4-1: Configuring Cisco ISE Guest Services
Lab 5-1: BYOD On-Boarding using a Single SSID
Lab 5-2: Testing On-Boarding
Lab 7-1: Monitoring and Troubleshooting Cisco ISE (Optional)