Onboarding
Steps:
-
Step 1: Familiarize yourself with available Network Access Control
(NAC) content
- Task 1: Leverage the Network Access Control (NAC) Cisco Community page and resources page
- Step 2: Complete Smart Account setup
- Step 3: Validate Identity Services Engine (ISE) licenses
-
Step 4: Enable Telemetry
- Task 7: Enable ISE Telemetry
-
Step 5: Evaluate your security requirements
- Task 8: Evaluate the security needs in your environment
-
Step 6: Review compatibility and installation guides
- Task 9: Plan to review the installation and compatibility guides
Implement
Steps
-
Step 1: Perform post installation tasks
- Task 1: Review ISE performance and scale guide to determine the size of deployment needed
- Task 2: Review port reference guide and open the required firewall ports for features that will be in use
- Task 3: Review ISE Security Settings and disable the weak ciphers that are not in use. Then import certification authority (CA) signed certificates if needed
- Task 4: Create Command Live Line (CLI) and Web Administration with required roles and monitor ISE Alarms
- Step 2: Configure scheduled backups and purge policies
-
Step 3: Validate ISE is not on evaluation licenses
- Task 7: Ensure ISE is registered to a Smart Account
-
Step 4: Set up an ISE deployment successfully
- Task 8: Create an ISE deployment
Use
Steps
- Step 1: Set up an ISE deployment successfully
-
Step 2: Create ISE policy sets
- Task 4: Create ISE policy sets for wired, wireless, VPN network access, and guest access
-
Step 3: Ensure that network access is functioning successfully
- Task 5: Update policy conditions and results
Engage
Steps
- Step 1: Validate your deployment against any critical errors
-
Step 2: Scale your network access
- Task 3: Ensure that the minimum number of deployed licenses aligns with the size of the deployment
Adopt
Steps
-
Step 1: Familiarize yourself with common system maintenance tasks
- Task 1: Review the maintain and monitor section of the ISE administrator guide and implement as necessary
-
Step 2: Scale your network access
- Task 2: Ensure that the minimum number of deployed licenses aligns with the size of the deployment
-
Step 3: Identify and enable the ISE nodes to be used for device administration with TACACS+
- Task 3: Ensure smart account has adequate device administration licenses
- Task 4: Learn about guest types, explore and build guest portals, and create policy sets for guest access
-
Step 4: Validate failover
- Task 5: Validate failover and high availability for the different ISE personas
-
Step 5: Leverage ISE Reports
- Task 6: Explore device administration and guest reports to ensure that access and authorization are working as intended. Plan to update policies as needed.
Comments
0 comments
Please sign in to leave a comment.