4levels teams with the top technology providers to enhance your operations   |   Domains & Hosting   |  Get Support   | My 4levels
GET IN TOUCH
+27 (0)11 848 6229

Cisco

4levels-IT-Default-Header

Implementing and Configuring Cisco Identity Services Engine v2.1


Course Description


Overview

Implementing and Configuring Cisco Identity Services Engine v2.1 (SISE) is an identity and access control policy platform that provides a single policy plane across the entire organization, combining multiple services into a single context-aware identity-based platform. You will learn how to configure and administer many of the services, including authentication, authorization and accounting (AAA), posture, profiling, device on-boarding and guest management. You will also learn the knowledge and skills to enforce security posture compliance for wired and wireless endpoints and enhance infrastructure security using the Cisco ISE.  

Audience

  • ISE Administrators/Engineers
  • Wireless Administrators/Engineers
  • Consulting Systems Engineers
  • Technical/Wireless/BYOD/Security Solutions Architects
  • ATP partner systems and field engineers
  • Systems integrators who install and implement the Cisco Identity Service Engine version 2.1
 

Prerequisites

The knowledge and skills that a learner should possess before attending this course are as follows:
  • Familiarity with Cisco IOS CLI
  • Familiarity with Cisco ASA
  • Familiarity with Cisco VPN clients
  • Familiarity with Microsoft Windows operating systems
  • Familiarity with 802.1X
 

Key topics

Module 1: Introducing Cisco ISE Architecture and Deployment
  • Security challenges
  • Cisco ISE solutions Use Cases
    • Guest use
    • BYOD
    • Profiling
    • Compliance
    • Security group access
  • Secure Access Control
  • ISE function
  • ISE deployment components
    • Admin node
    • Policy service node
    • Monitoring node
    • pxGrid Services
    • Policy synchronization
    • Deployment options
  • Context visibility
    • Benefits
    • Wizard
    • Streamline wizard
Module 2: Cisco ISE Policy Enforcement
  • IEEE 802.1X primeer
  • MAC authentication bypass
  • 802.1X and MAB
  • Identity sources
  • Multi-AD overview and configuration
  • Lightweight directory access protocol
  • RADIUS
  • SAMLv2
  • Identity source sequence
  • Certification authority services
  • Authentication and authorization process
  • Exception policies and policy sets
  • Global vs local exception processing
  • Third-party NAD support
  • Cisco TrustSec
  • Easy connect
    • Overview
    • Modes and flows
    • Configuration
Module 3: Web Auth & Guest Services
  • Web authentication overview
  • Guest access services overview
  • Guest access settings
  • ISE sponsor components and configuration
Module 4: Cisco ISE Profiler
  • Profiler service and policies
    • Configure
    • Prepare
    • Enable
    • Probe configuration
    • Feed service
    • Settings
    • Profiling parameters
  • NMAP scan action
Module 5: Cisco ISE BYOD
  • Problem and solutions
  • Design
  • Portal selection process
  • Device portal configuration
  • ISE CA server and local certificates
Module 6: Cisco ISE Endpoint Compliance Services
  • Posture service
    • Conditions
    • Compliance module
    • Flow
    • Agents
    • Deployment and licensing
  • Client provisioning
  • Posture general settings
  • Client provisioning portal and policy
Module 7: Cisco ISE with AMP and VPN-Based Services
  • AAA – external authentication
  • Cisco ASA for VPN authentication
  • Threat centric NAC
Module 8: Cisco ISE Integrated Solutions with APIs
  • Location-based authorization
  • pxGrid framework
Module 9: Working with Network Access Devices
  • TACACS+
    • Device administration
    • Configuration
    • Guidelines
    • Best practices
  • Migrating Cisco ACS to ISE
Module 10: Cisco ISE Design (Self-Study)
  • ISE planning and Pre-deployment
  • ISE sizing and scaling practices
  • Deployment best practices
  • Web portals best practices
  • PSN HA or load sharing
  • Deploying monitoring personas
  • Network infrastructure preparation
Module 11: Configuring Thrid Party NAD Support (optional/Self-Study/Reference)
  • Third-party NAD support configuration
Labs:
  • Initial Configuration of Cisco ISE
  • Complete Cisco ISE GUI Setup
  • Integrate Cisco ISE with Active Directory
  • Integrating Cisco ISE with a second Microsoft Active Directory
  • Basic Policy Configuration
  • Configure Guest Access
  • Guest Access Operations
  • Guest Reports
  • Configuring Profiling
  • Customizing the Cisco ISE Profiling Configuration
  • ISE Profiling Reports
  • BYOD Configuration
  • Device Blacklisting
  • Compliance
  • Configuring Client Provisioning
  • Configuring Posture Policies
  • Testing and Monitoring Compliance Based Access
  • Compliance Policy Testing
  • MDM Integration with Cisco ISE
  • MDM Access and Configuration
  • Client Access with MDM
  • Using Cisco ISE for VPN Access
  • Configuring Backups and Patching
  • Configuring Administrative Access
  • Review of General Tools
  • Report Operations
 

Objectives

After the completion of this course you will be able to:
  • Describe Cisco ISE architecture, installation, and distributed deployment options
  • Configure Network Access Devices (NADs), policy components, and basic authentication and authorization policies in Cisco ISE - Implement Cisco ISE web authentication and guest services
  • Deploy Cisco ISE profiling, posture and client provisioning services
  • Describe administration, monitoring, troubleshooting, and TrustSec SGA security
  • Configure device administration using TACACS+ in Cisco ISE

Course Duration

5 Days
  • Brands we have partnered with to add value to your business


    We are committed to helping our clients reach their business goals

    4levels’ preferred access to the latest technologies, premier technical support and advanced training helps provide you with specialist and customized solutions that help you achieve your business goals.

4levels Solutions sign up form


Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur excepteur sint occaecat cupidatat non

4levels Solutionslogin form