Architecture & Deployment Flashcards
2 Types of Identities used by ISE
Username & MAC address
2 Types of Identity Stores used by ISE
Internal & External
ISE internal Identity Stores are used to authenticate which type of identities
Users & Endpoints
Which Identity Store attributes can be used in ISE authorization policy
User & Machine
What is an individual Identity Store called
Identity Source
How is Identity Source Sequence processed
Top Down
WHich Idnetity Stores are suported by ISE for authentication
LDAP
Microsoft AD
RADIUS server
MAB uses which type of Identity Store
Internal Identity store
2 Types of Internal Identity Store used by ISE
User database
Endpoint Database
Primary reason for using external Identity Store
Performance
Scalability
What is an Identity Store
Database which can be used to authenticate User or Endpoint credentials
Minimum certificate checks
Has Certificate been signed by a Trusted CA
Is certificate expired
Has certificate been revoked
Has client provided proof of possesion
ISE Node Types
Policy Admin Node
Policy Services Node
Monitoring & Troubleshooting Node
pxGrid
Policy Admin Node (PAN)
Node used to manage configuration changes to all nodes in the deployment.
These changes are then synced between Primary PAN and Backup PAN (and config updated to each PSN where applicable)
Policy Services Node (PSN)
Node used to provide Network access, Posture, Client Provisioning, Profiling Apply Authentication and Authorization Policies to endpoints
Monitoring & Troubleshoting (MnT)
Node used to provides advanced troubleshooting options and stores monitoring logs.
pxGrid
Node used to share context-sensitive data with approved 3rd party applications
How Node Groups work
All PSNs are on same VLAN and maintain a heartbeat with each other.
If PSN dies while servicing an authentication request another PSN sends CoA to NAD which causes endpoint to restart session establishment.
Most commonly used behind Load Balancers
ISE Personas
PAN
MnT
PSN
Configure ISE Personas
Administration > System > Deployment > Select node
Configure ISE as Primary PAN
Administration > System > Deployment
Select Node > Edit
Select Make Primary
Save
Installing ISE Patches
Download Patch
Go to Administration > System > Maintenance > Patch Management
Select Install
Browse to Patch
Select Install
Confirm Md5 hash
Patch will be applied to all nodes in deployment
Which Personas are configured in a Standalone Deployment
PAN
PSN
Which Persona needs the latgest amont of storage
MnT
Initial certificate presented by ISE is which type
Self-Signed
Where can Authentication & Authorization sessions be viewed for troubleshooting purposes
Operations > Live Logs > TACACS+/RADIUS Live Logs
Which details can be added to NAD when configuring in ISE
Device Name
IP address
RADIUS shared secret
What is the Authentication Policy used for
Identify user or endpoint as they connect to the network
Which Profiling Policies are available
Netflow DHCP DHCPSPAN HTTP RADIUS NMAP DNS SNMPQUERY/SNMPTRAP ACTIVE DIRECTORY