Cisco ISE
Cisco ISE
Cisco ISE
ENGINE (ISE)
Cisco ISE is the centralized AAA and policy engine
solution from Cisco. Cisco ISE integrates with
numerous Cisco products and third-party solutions to
allow you to maintain visibility of who and what is
accessing your network, and to enforce access control
consistently.
The following are some of the benefits of Cisco ISE:
• Centralizes network access control for wired,
wireless, or VPN users.
• Helps administrators to comply with security
regulations and audits by providing for easy policy
creation, visibility, and reporting across the
organization. Administrators can easily perform
audits for regulatory requirements and mandated
guidelines.
• Allows administrators to match users, endpoints,
and each endpoint’s security posture. It can also
process attributes such as location, the time the
user logged in or logged off, and the access
method.
• Provides network visibility and host identification
by supporting profiling capabilities. Profiling
allows you to obtain real-time and historical
visibility of all the devices on the network.
• Simplifies the experience of guest users or
contractors when accessing the network. Cisco ISE
provides self-service registration and fully
customizable, branded guest portals that you can
configure in minutes.
• Provides great support for bring-your-own-device
(BYOD) and enterprise mobility also, with selfservice
device onboarding and management.
• Supports internal device certificate management
and integration with enterprise mobility
management (EMM) partners.
• Supports software-defined segmentation policies
for users, endpoints, and other devices on your
network based on security policies.
• Leverages Cisco TrustSec technology to define
context-based access control policies using
security group tags (SGTs). SGTs make
segmentation easier when used in a security group
ACL (SGACL).
• Uses the Cisco Platform Exchange Grid (pxGrid)
technology to integrate with other Cisco products
and third-party solutions. pxGrid allows you to
maintain threat visibility and fast-tracks the
capabilities to detect, investigate, contain, and
recover (remediate) security incidents.
• Supports TACACS+ and RADIUS AAA services, as
well as integration with Duo for multifactor
authentication and secure access. Cisco ISE also
supports external authentication servers such as
LDAP and Active Directory servers.
Cisco ISE can be deployed in a physical appliance or in
virtual machines (VMs). You can create physical or
virtual ISE clusters for greater scalability, redundancy,
and failover.