Architecture & Deployment Flashcards

1
Q

2 Types of Identities used by ISE

A

Username & MAC address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

2 Types of Identity Stores used by ISE

A

Internal & External

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISE internal Identity Stores are used to authenticate which type of identities

A

Users & Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Identity Store attributes can be used in ISE authorization policy

A

User & Machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an individual Identity Store called

A

Identity Source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How is Identity Source Sequence processed

A

Top Down

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

WHich Idnetity Stores are suported by ISE for authentication

A

LDAP
Microsoft AD
RADIUS server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

MAB uses which type of Identity Store

A

Internal Identity store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

2 Types of Internal Identity Store used by ISE

A

User database

Endpoint Database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Primary reason for using external Identity Store

A

Performance

Scalability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an Identity Store

A

Database which can be used to authenticate User or Endpoint credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Minimum certificate checks

A

Has Certificate been signed by a Trusted CA
Is certificate expired
Has certificate been revoked
Has client provided proof of possesion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ISE Node Types

A

Policy Admin Node
Policy Services Node
Monitoring & Troubleshooting Node
pxGrid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Policy Admin Node (PAN)

A

Node used to manage configuration changes to all nodes in the deployment.
These changes are then synced between Primary PAN and Backup PAN (and config updated to each PSN where applicable)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Policy Services Node (PSN)

A
Node used to provide 
Network access, 
Posture, 
Client Provisioning, 
Profiling
Apply Authentication and Authorization Policies to endpoints
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Monitoring & Troubleshoting (MnT)

A

Node used to provides advanced troubleshooting options and stores monitoring logs.

17
Q

pxGrid

A

Node used to share context-sensitive data with approved 3rd party applications

18
Q

How Node Groups work

A

All PSNs are on same VLAN and maintain a heartbeat with each other.
If PSN dies while servicing an authentication request another PSN sends CoA to NAD which causes endpoint to restart session establishment.
Most commonly used behind Load Balancers

19
Q

ISE Personas

A

PAN
MnT
PSN

20
Q

Configure ISE Personas

A

Administration > System > Deployment > Select node

21
Q

Configure ISE as Primary PAN

A

Administration > System > Deployment
Select Node > Edit
Select Make Primary
Save

22
Q

Installing ISE Patches

A

Download Patch
Go to Administration > System > Maintenance > Patch Management
Select Install
Browse to Patch
Select Install
Confirm Md5 hash
Patch will be applied to all nodes in deployment

23
Q

Which Personas are configured in a Standalone Deployment

A

PAN

PSN

24
Q

Which Persona needs the latgest amont of storage

A

MnT

25
Q

Initial certificate presented by ISE is which type

A

Self-Signed

26
Q

Where can Authentication & Authorization sessions be viewed for troubleshooting purposes

A

Operations > Live Logs > TACACS+/RADIUS Live Logs

27
Q

Which details can be added to NAD when configuring in ISE

A

Device Name
IP address
RADIUS shared secret

28
Q

What is the Authentication Policy used for

A

Identify user or endpoint as they connect to the network

29
Q

Which Profiling Policies are available

A
Netflow
DHCP
DHCPSPAN
HTTP
RADIUS
NMAP
DNS
SNMPQUERY/SNMPTRAP
ACTIVE DIRECTORY