Configure and Troubleshoot ISE with External LDAPS Identity Store

Introduction

This document details the integration of Cisco Identity Services Engine (ISE) with a Secure LDAPS server, serving as an external identity source. It outlines the necessary steps for configuration and troubleshooting to ensure seamless network authentication.

Prerequisites

Before proceeding, users should possess a foundational understanding of Identity Service Engine (ISE) administration and Active Directory/Secure Lightweight Directory Access Protocol (LDAPS).

Components Used

The configuration described in this guide is based on the following software and hardware versions:

  • Cisco ISE 2.6 Patch 7
  • Microsoft Windows Server 2012 R2 with Active Directory Lightweight Directory Services
  • Windows 10 OS PC with native supplicant and user certificate
  • Cisco Switch C3750X with 152-2.E6 image

The procedures were developed in a lab environment using default configurations. Users operating in live networks should carefully consider the potential impact of any commands.

Key Configuration Steps

  • Configure LDAPS on Active Directory, including certificate installation.
  • Integrate ISE with the LDAPS Server by importing certificates and configuring LDAP attributes.
  • Configure the network switch for 802.1x authentication.
  • Configure the endpoint for EAP-TLS authentication.
  • Set up the Policy Set on ISE for authentication and authorization.

Verification

The document provides methods to verify the successful integration and authentication, including checking authentication sessions and performing test binds to the server.

Troubleshooting

Common errors encountered during the configuration process are addressed, offering guidance on resolving issues such as unsupported authentication methods and certificate validation failures.

Related Information

For further details and related configurations, refer to the following Cisco resources:

Models: ISE Identity Services Engine, ISE, Identity Services Engine, Services Engine

File Info : application/pdf, 21 Pages, 2.47MB

PDF preview unavailable. Download the PDF instead.

216190-configure-and-troubleshoot-ise-with-exte

References

iText pdfHTML 4.0.5 (AGPL version) ©2000-2023 iText Group NV

Related Documents

Preview Cisco ISE Upgrade Guide: Ask the Experts
A comprehensive guide to upgrading Cisco Identity Services Engine (ISE) software, covering reasons for upgrading, planning, execution, and post-upgrade tasks. Includes details on release cycles, platform support, licensing, and upgrade options (split and full).
Preview Cisco ISE アップグレードとバージョン3.3の新機能 | Ask the Experts
Cisco Identity Services Engine (ISE) のバージョン3.3へのアップグレードに関する専門家向けセッション。新機能、リリースサイクル、互換性、ライセンスモデル、アップグレードパスを解説。
Preview Cisco Identity Services Engine (ISE) v2.6: Common Criteria Operational User Guidance
This document provides comprehensive operational user guidance and preparative procedures for Cisco Identity Services Engine (ISE) version 2.6, focusing on its Common Criteria evaluated configuration, installation, and administration for network security professionals.
Preview Cisco ISE Licensing Migration Guide
A comprehensive guide to migrating Cisco Identity Services Engine (ISE) licenses from older versions to the new Smart Licensing scheme, including VM Common licenses and Base, Plus, and Apex licenses to Essentials, Advantage, and Premier.
Preview Cisco Firepower: Introduction to Network Discovery and Identity
A comprehensive guide to network discovery, host and application data, user identity management, and NetFlow data within the Cisco Firepower System, detailing its features for network visibility, security, and control.
Preview Cisco ISE-PIC Installation and Upgrade Guide, Release 3.3
Comprehensive guide for installing and upgrading Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) software, detailing prerequisites, installation steps, upgrade procedures, and troubleshooting for network administrators.
Preview Cisco ISE 3.0 Upgrade Guide: Overview
Comprehensive guide to upgrading Cisco Identity Services Engine (ISE) to version 3.0, covering upgrade paths, licensing changes, smart licensing for air-gapped networks, and VM license categories. Includes procedures for configuring SSM On-Prem and understanding Permanent License Reservation.
Preview Cisco Secure Network Analytics ISE and ISE-PIC Configuration Guide 7.5.3
This guide details the integration of Cisco Secure Network Analytics (formerly Stealthwatch) v7.5.3 with Cisco Identity Services Engine (ISE) via pxGrid, covering essential certificate deployment and host group automation configurations for enhanced network security and visibility.