Cisco ISE 3.3 Installation Overview
Cisco ISE 3.3 Installation Overview
3
First Published: 2023-07-05
Last Modified: 2025-03-18
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
[Link]
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-0883
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS,
INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH
THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY,
CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of
the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS.
CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT
LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS
HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network
topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional
and coincidental.
All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.
Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at [Link]/go/offices.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL:
[Link] Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. (1721R)
© 2025 Cisco Systems, Inc. All rights reserved.
CONTENTS
Additional References 1
Communications, services, and additional information 1
Cisco Bug Search Tool 2
Documentation feedback 2
Cisco ISE Network Architecture 2
Cisco ISE Deployment Terminology 2
Node Types and Personas in Distributed Deployments 3
Administration Node 3
Policy Service Node 3
Monitoring Node 3
pxGrid Node 4
Standalone and Distributed ISE Deployments 4
Distributed Deployment Scenarios 4
Small Network Deployments 4
Split Deployments 5
Medium-Sized Network Deployments 6
Large Network Deployments 7
Centralized Logging 7
Using Load Balancers in Centralized Networks 7
Dispersed Network Deployments in Cisco ISE 8
Considerations for Planning a Network with Several Remote Sites 9
Cisco ISE Deployment Sizing Guidelines 9
Switch and Wireless LAN Controller Configuration Required to Support Cisco ISE Functions 10
CHAPTER 2 Cisco Secured Network Server Series Appliances and Virtual Machine Requirements 11
Tools Used to Create Bootable USB Device from Installation ISO File 41
SNS Appliance Reference 42
Create a Bootable USB Device Using Rufus 42
Reimage the Cisco SNS Hardware Appliance 43
VMware Virtual Machine 43
Virtual Machine Resource and Performance Checks 43
Install Cisco ISE on VMware Virtual Machine Using the ISO File 44
Prerequisites for Configuring a VMware ESXi Server 44
Connect to the VMware Server Using the Serial Console 45
Configure a VMware Server 46
Increase Virtual Machine Power-On Boot Delay Configuration 47
Automatic Installation in Virtual Machine Using the ZTP Configuration Image File 76
Automatic Installation in Virtual Machine using VM User Data 78
Automatic Installation in Appliance 80
Automatic Installation in Appliance Using the ZTP Configuration Image File 80
Trigger Automatic Installation using UCS XML APIs 81
OVA Automatic Installation 84
Automatic OVA Installation Using the ZTP Configuration Image File 85
OVA Automatic Installation Using the VM User Data 87
Creating the ZTP Configuration Image File 89
VM User Data 90
Additional References
See Cisco ISE End-User Resources for additional resources that you can use when working with Cisco ISE.
Documentation feedback
To provide feedback about Cisco technical documentation, use the feedback form available in the right pane
of every online document.
• Network resources
• Endpoints
The policy information point represents the point at which external information is communicated to the Policy
Service persona. For example, external information could be a Lightweight Directory Access Protocol (LDAP)
attribute.
Term Definition
Node Type The Cisco ISE node can assume any of the following personas:
Administration, Policy Service, Monitoring
Term Definition
Administration Node
A Cisco ISE node with the Administration persona allows you to perform all administrative operations on
Cisco ISE. It handles all system-related configurations that are related to functionality such as authentication,
authorization, and accounting. In a distributed deployment, you can have a maximum of two nodes running
the Administration persona. The Administration persona can take on the standalone, primary, or secondary
role.
Monitoring Node
A Cisco ISE node with the Monitoring persona functions as the log collector and stores log messages from
all the Administration and Policy Service nodes in a network. This persona provides advanced monitoring
and troubleshooting tools that you can use to effectively manage a network and resources. A node with this
persona aggregates and correlates the data that it collects, and provides you with meaningful reports. Cisco
ISE allows you to have a maximum of two nodes with this persona, and they can take on primary or secondary
roles for high availability. Both the primary and secondary Monitoring nodes collect log messages. In case
the primary Monitoring node goes down, the secondary Monitoring node automatically becomes the primary
Monitoring node.
At least one node in your distributed setup should assume the Monitoring persona. We recommend that you
do not have the Monitoring and Policy Service personas enabled on the same Cisco ISE node. We recommend
that the Monitoring node be dedicated solely to monitoring for optimum performance.
pxGrid Node
You can use Cisco pxGrid to share the context-sensitive information from Cisco ISE session directory with
other network systems such as ISE Eco system partner systems and other Cisco platforms. The pxGrid
framework can also be used to exchange policy and configuration data between nodes like sharing tags and
policy objects between Cisco ISE and third party vendors, and for other information exchanges. Cisco pxGrid
also allows third party systems to invoke adaptive network control actions (EPS) to quarantine users/devices
in response to a network or security event. The TrustSec information like tag definition, value, and description
can be passed from Cisco ISE via TrustSec topic to other networks. The endpoint profiles with Fully Qualified
Names (FQNs) can be passed from Cisco ISE to other networks through a endpoint profile meta topic. Cisco
pxGrid also supports bulk download of tags and endpoint profiles.
You can publish and subscribe to SXP bindings (IP-SGT mappings) through pxGrid. For more information
about SXP bindings, see Security Group Tag Exchange Protocol section in Cisco Identity Services Engine
Administrator Guide.
In a high-availability configuration, Cisco pxGrid servers replicate information between the nodes through
the PAN. When the PAN goes down, pxGrid server stops handling the client registration and subscription.
You need to manually promote the PAN for the pxGrid server to become active.
The primary node provides all the configuration, authentication, and policy capabilities that are required for
this network model, and the secondary Cisco ISE node functions in a backup role. The secondary node supports
the primary node and maintains a functioning network whenever connectivity is lost between the primary
node and network appliances, network resources, or RADIUS.
Centralized authentication, authorization, and accounting (AAA) operations between clients and the primary
Cisco ISE node are performed using the RADIUS protocol. Cisco ISE synchronizes or replicates all of the
content that resides on the primary Cisco ISE node with the secondary Cisco ISE node. Thus, your secondary
node is current with the state of your primary node. In a small network deployment, this type of configuration
model allows you to configure both your primary and secondary nodes on all RADIUS clients by using this
type of deployment or a similar approach.
Figure 1: A Small Network Deployment of Cisco ISE nodes
As the number of devices, network resources, users, and AAA clients increases in your network environment,
you should change your deployment configuration from the basic small model and use more of a split or
distributed deployment model.
Split Deployments
In split Cisco ISE deployments, you continue to maintain primary and secondary nodes as described in a small
Cisco ISE deployment. However, the AAA load is split between the two Cisco ISE nodes to optimize the
AAA workflow. Each Cisco ISE appliance (primary or secondary) needs to be able to handle the full workload
if there are any problems with AAA connectivity. Neither the primary node nor the secondary nodes handles
all AAA requests during normal network operations because this workload is distributed between the two
nodes.
The ability to split the load in this way directly reduces the stress on each Cisco ISE node in the system. In
addition, splitting the load provides better loading while the functional status of the secondary node is
maintained during the course of normal network operations.
In split Cisco ISE deployments, each node can perform its own specific operations, such as network admission
or device administration, and still perform all the AAA functions in the event of a failure. If you have two
Cisco ISE nodes that process authentication requests and collect accounting data from AAA clients, we
recommend that you set up one of the Cisco ISE nodes to act as a log collector.
In addition, the split Cisco ISE deployment design provides an advantage because it allows for growth.
Figure 2: Split Network Deployment in Cisco ISE
Note In a medium-sized network deployment, you cannot enable the Policy Service persona on a node that runs
the Administration persona, Monitoring persona, or both. You need dedicated policy service node(s).
As the amount of log traffic increases in a network, you can choose to dedicate one or two of the secondary
Cisco ISE nodes for log collection in your network.
Note Harden your virtual environment and ensure that all the security updates are up-to-date. Cisco is not liable
for any security issues found in hypervisors.
Note Cisco ISE does not support VM snapshots for backing up ISE data on any of the virtual environments (VMware,
Linux KVM, Microsoft Hyper-V, and Nutanix AHV) because a VM snapshot saves the status of a VM at a
given point in time. In a multi-node Cisco ISE deployment, data in all the nodes are continuously synchronized
with current database information. Restoring a snapshot might cause database replication and synchronization
issues. We recommend that you use the backup functionality included in Cisco ISE for archival and restoration
of data. Using snapshots to back up ISE data results in stopping Cisco ISE services. A reboot is required to
bring up the ISE node.
Caution If the Snapshot feature is enabled on the VM, it might corrupt the VM configuration. If this issue occurs, you
might have to reimage the VM and disable VM snapshot.
The Cisco SNS 3715 appliance is designed for small deployments. Cisco SNS 3755 and Cisco SNS 3795
appliances have several redundant components such as hard disks and power supplies and are suitable for
larger deployments that require highly reliable system configurations. Cisco SNS 3795 is recommended for
PAN and MnT personas.
Cisco ISE Release 3.1 Patch 6 and above and Cisco ISE Release 3.2 Patch 2 and above versions support Cisco
SNS 3700 series appliances.
The following table describes the hardware specifications of Cisco SNS 3700 series appliances.
Note • You cannot add additional hardware resources like memory, processor, or hard disk to a Cisco SNS 3700
series appliance.
• Installing Cisco ISE on SNS hardware appliance requires at least six NICs. By default, all SNS hardware
appliances are delivered with six NICs.
• Mixing SAS/SATA hard drives and SAS/SATA SSDs is not supported. You must use either SAS/SATA
hard drives or SAS/SATA SSDs.
• SSD offers improved performance in disk read/write operations and other Cisco ISE operations like boot,
installation, upgrade, and database-intensive tasks like backup, reports generation, and so on.
• SFPs must be ordered separately. For component part numbers, see Cisco UCS C-Series Rack Server
Data Sheet.
For more information, see the Cisco SNS-3700 Series Appliance Hardware Installation Guide.
3. Create a cluster on vCenter and add the ESXi host to the cluster.
4. Create a new VM in the cluster.
5. In the Customize Hardware window, choose Add New Device > Trusted Platform Module.
You must disable the Secure Boot option. Ensure that the Encryption option is set as Required.
6. Map the Cisco ISE ISO to the new VM and complete the installation.
Note You must use the application stop command before using the halt command or
powering off the VM to prevent database corruption issues.
The following OVA templates can be used for SNS 3600 series appliances:
Cisco-vISE-300-[Link].ova Evaluation
Extra Small
Small
Medium
Cisco-vISE-600-[Link].ova Small
Medium
Cisco-vISE-1200-[Link].ova Medium
Large
Cisco-vISE-1800-[Link].ova Large
Cisco-vISE-2400-[Link].ova Large
The following OVA templates can be used for both SNS 3600 and SNS 3700 series appliances:
Small 300-Small_36xx
300-Small_37xx
Medium 300-Medium_36xx
300-Medium_37xx
600-Small_37xx
Medium 600-Medium_36xx
600-Medium_37xx
1200-Medium_37xx
Large 1200-Large_36xx
1200-Large_37xx
2400-Large_37xx
The 300 GB OVA templates are sufficient for Cisco ISE nodes that serve as dedicated Policy Service or
pxGrid nodes.
The 600 GB and 1.2 TB OVA templates are recommended to meet the minimum requirements for ISE nodes
that run the Administration or Monitoring persona.
If you need to customize the disk size, CPU, or memory allocation, you can manually deploy Cisco ISE using
the standard .iso image. However, it is important that you ensure the minimum requirements and resource
reservations specified in this document are met. The OVA templates simplify ISE virtual appliance deployment
by automatically applying the minimum resources required for each platform.
Evaluation 4 No 16 No reservation.
reservation.
Extra Small 8 8 32 32
Note • You can enable only the PSN persona on Extra Small VM. PAN and MnT personas are not supported
for this node.
• Extra Small VM is supported only for deployments that have less than or up to 500,000 sessions.
We strongly recommend that you reserve CPU and memory resources to match the resource allocation. Failure
to do so may significantly impact ISE performance and stability.
For information about the supported operating systems, see Supported Operating System for Virtual Machines.
For information about the product specifications for Cisco SNS appliance, see Cisco Secure Network Server
Data Sheet.
The following table lists the VMware virtual machine requirements.
CPU • Evaluation
• Clock speed: 2.0 GHz or faster
• Number of CPU cores: 4 CPU cores
• Production
• Clock speed: 2.0 GHz or faster
• Number of cores:
• SNS 3600 Series Appliance:
• Extra Small: 8
• Small: 16
• Medium: 24
• Large: 24
Note
The number of cores is twice of that present in equivalent of
the Cisco Secure Network Server 3600 series, due to
hyperthreading. For example, in case of Small network
deployment, you must allocate 16 vCPU cores to meet the
CPU specification of SNS 3615, which has 8 CPU Cores or
16 Threads.
Memory • Evaluation: 16 GB
• Production
• Extra Small: 32 GB
• Small: 32 GB for SNS 3615 and SNS 3715
• Medium: 96 GB for SNS 3655 and SNS 3755
• Large: 256 GB for SNS 3695 and SNS 3795
Storage and File System The storage system for the Cisco ISE virtual appliance requires a minimum write
performance of 50 MB per second and a read performance of 300 MB per second.
Deploy a storage system that meets these performance criteria and is supported by
VMware server.
You can use the show tech-support command to view the read and write
performance metrics.
We recommend the VMFS file system because it is most extensively tested, but
other file systems, transports, and media can also be deployed provided they meet
the above requirements.
NIC 1 NIC interface required (two or more NICs are recommended; six NICs are
supported). Cisco ISE supports E1000E and VMXNET3 adapters.
Note
You have to remap the ESXi adapter to synchronize it with the ISE adapter order.
VMware Virtual • OVA templates: VMware version 14 or higher on ESXi 6.7, ESXi 7.0, and
Hardware ESXi 8.0.
Version/Hypervisor
• ISO file supports ESXi 6.7, ESXi 7.0, and ESXi 8.0.
CPU • Evaluation
• Clock Speed: 2.0 GHz or faster
• Number of Cores: 4 CPU cores
• Production
• Clock Speed: 2.0 GHz or faster
• Number of Cores:
• SNS 3600 Series Appliance:
• Extra Small: 8
• Small: 16
• Medium: 24
• Large: 24
Note
The number of cores is twice of that present in
equivalent of the Cisco Secure Network Server
3600 series, due to hyperthreading. For
example, in case of Small network deployment,
you must allocate 16 vCPU cores to meet the
CPU specification of SNS 3615, which has 8
CPU Cores or 16 Threads.
Memory • Evaluation: 16 GB
• Production
• Extra Small: 32 GB
• Small: 32 GB for SNS 3615 and SNS 3715
• Medium: 96 GB for SNS 3655 and SNS 3755
• Large: 256 GB for SNS 3695 and SNS 3795
KVM Disk Device Disk bus - virtio, cache mode - none, I/O mode - native
Use preallocated RAW storage format.
NIC 1 NIC interface required (two or more NICs are recommended; six
NICs are supported). Cisco ISE supports VirtIO drivers. We
recommend VirtIO drivers for better performance.
CPU • Evaluation
• Clock speed: 2.0 GHz or faster
• Number of cores: 4 CPU cores
• Production
• Clock speed: 2.0 GHz or faster
• Number of Cores:
• SNS 3600 Series Appliance:
• Extra Small: 8
• Small: 16
• Medium: 24
• Large: 24
Note
The number of cores is twice of that present in equivalent of the Cisco
Secure Network Server 3600 series, due to hyperthreading. For
example, in case of Small network deployment, you must allocate 16
vCPU cores to meet the CPU specification of SNS 3615, which has
8 CPU Cores or 16 Threads.
Memory • Evaluation: 16 GB
• Production
• Extra Small: 32 GB
• Small: 32 GB for SNS 3615 and SNS 3715
• Medium: 96 GB for SNS 3655 and SNS 3755
• Large: 256 GB for SNS 3695 and SNS 3795
Note
When you create the Virtual Machine for Cisco ISE, use a single virtual disk that meets
the storage requirement. If you use more than one virtual disk to meet the disk space
requirement, the installer may not recognize all the disk space.
NIC 1 NIC interface required (two or more NICs are recommended; six NICs are supported).
Note Cisco ISE supports Azure Stack HCI 23H2 and later versions. The virtual machine requirements and the
installation procedure for the Cisco ISE VMs in the Azure Stack HCI are the same as that of Microsoft
Hyper-V.
Small 16 16 32 32 600 GB
Medium 24 24 96 96 1.2 TB
Large 24 24 256 256 2.4 TB (4*600 GB)
You must do the following configuration on Nutanix AHV before proceeding with Cisco ISE installation:
• Create a virtual machine (VM) on Nutanix AHV and keep the VM powered off.
• If you are using AOS 6.8 or earlier versions, access the Nutanix CVM using ssh login and run the
following commands:
• <acropolis> vm.serial_port_create <Cisco ISE VM Name> type=kServer index=0
• <acropolis> [Link] <Cisco ISE VM Name> disable_branding=true
• <acropolis> [Link] <Cisco ISE VM Name> disable_hyperv=true
If you are using AOS 7.0, access the Nutanix CVM using ssh login and run the following commands:
• <acropolis> vm.serial_port_create <Cisco ISE VM Name> type=kServer index=0
• <acropolis> [Link] <Cisco ISE VM Name> disable_branding=true
• Exit Acropolis CLI and power on the VM to proceed with Cisco ISE installation using the standard .iso
image.
CPU • Evaluation:
• Clock Speed: 2.0 GHz or faster
• Number of Cores: 2 CPU cores
• Production:
• Clock Speed: 2.0 GHz or faster
• Number of Cores
• Extra Small—8 processors (4 cores with hyperthreading enabled)
• Small—12 processors (6 cores with hyperthreading enabled)
• Large—16 processors (8 cores with hyperthreading enabled)
Memory • Evaluation:
• Basic—4 GB (for evaluating guest access and basic access policy flows)
• Advanced—16 GB (for evaluating advanced features such as pxGrid,
Internal CA, SXP, Device Administration, and Passive Identity Services)
• Production:
• Small—16 GB
• Large—64 GB
NIC 1 GB NIC interface required (two or more NICs are recommended; six NICs are
supported). Cisco ISE supports VirtIO drivers. We recommend VirtIO drivers for
better performance.
Important For information on deploying Cisco ISE on cloud platforms, see Deploy Cisco Identity Services Engine
Natively on Cloud Platforms.
For more information on deploying Cisco ISE on cloud platforms, see Deploy Cisco Identity Services Engine
Natively on Cloud Platforms.
across multiple guest VMs. Deploying Cisco ISE virtual appliances using the OVF templates ensures
that adequate resources are assigned to each VM. If you do not use OVF templates, then ensure that you
assign the equivalent resource reservations when you manually install Cisco ISE using the ISO image.
Note If you choose to deploy Cisco ISE manually without the recommended
reservations, you must assume the responsibility to closely monitor your
appliance’s resource utilization and increase resources, as needed, to ensure proper
health and functioning of the Cisco ISE deployment.
• If you are using the OVA templates for installation, check the following settings after the installation is
complete:
• Ensure that you assign the resource reservations that are specified in the VMware Virtual Machine
Requirements for Cisco ISE, on page 14 section in the CPU/Memory Reservation field (under the
Virtual Hardware tab in the Edit Settings window) to ensure proper health and functioning of the
Cisco ISE deployment.
• Ensure that the CPU usage in the CPU Limit field (under the Virtual Hardware tab in the Edit
Settings window) is set to Unlimited. Setting a limit for CPU usage (for example, setting the CPU
usage limit as 12000 MHz) will impact the system performance. If limit has been set, you must
shutdown the VM client, remove the limit, and the restart the VM client.
• Ensure that the memory usage in the Memory Limit field (under the Virtual Hardware tab in the
Edit Settings window) is set to Unlimited. Setting a limit for memory usage (for example, setting
the limit as 12000 MB) will impact the system performance.
• Ensure that the Shares option is set as High in the Hard Disk area (under the Virtual Hardware
tab in the Edit Settings window).
Admin and MnT nodes rely heavily on disk usage. Using shared disk storage VMware environment
might affect the disk performance. You must increase the number of disk shares allocated to a node
to increase the performance of the node.
• Policy Service nodes on VMs can be deployed with less disk space than Administration or Monitoring
nodes. The minimum disk space for any production Cisco ISE node is 300 GB.
• VMs can be configured with 1 to 6 NICs. The recommendation is to allow for 2 or more NICs. Additional
interfaces can be used to support various services such as profiling, guest services, or RADIUS.
Note If you decrease the RAM or CPU allocation for a VM, you must reimage Cisco ISE with the changed VM
configuration. However, increasing the RAM or CPU capacity does not require re-image.
Note You must change the firmware from BIOS to EFI in the boot mode of VM settings to boot GPT partition
with 2 TB or above.
Cisco ISE Persona Minimum Disk Minimum Disk Recommended Disk Maximum Disk
Space for Space for Space for Space
Evaluation Production Production
Note Additional disk space is required to store local debug logs, staging files, and to handle log data during upgrade,
when the Primary Administration node temporarily becomes a Monitoring node.
per day. In this case, you can store 76 days of logs in the Monitoring node, after which you must transfer
the old data to a repository and purge it from the Monitoring database.
For extra log storage, you can increase the VM disk space. For every 100 GB of disk space that you add, you
get 60 GB more for log storage.
If you increase the disk size of your virtual machine after initial installation, perform a fresh installation of
Cisco ISE. A fresh installation helps properly detect and utilize the full disk allocation.
The following table lists the number of days that RADIUS logs can be retained on your Monitoring node
based on the allocated disk space and the number of endpoints that connect to your network. The numbers
are based on the following assumptions: Ten or more authentications per day per endpoint with logging
suppression enabled.
150,000 17 51 86 172
200,000 13 38 65 129
250,000 11 31 52 104
500,000 6 16 26 52
The following table lists the number of days that TACACS+ logs can be retained on your Monitoring node
based on the allocated disk space and the number of endpoints that connect to your network. The numbers
are based on the following assumptions: The script runs against all NADs, 4 sessions per day, and 5 commands
per session.
75,000 17 51 86 172
100,000 13 38 65 129
Procedure
Note
• If the SNS appliances are placed in a remote location (for example, data centers), to which you do not have
any physical access and need to perform CIMC install from remote servers, it might take long hours for
installation. We recommend that you copy the ISO file on a USB drive and use that in the remote location
to speed up the installation process.
• Cisco ISE installation using CIMC may be affected by network speed, network stability, TCP segmentation,
or other factors of the operating system. This may impact the speed and the time taken (approximately 30
minutes) for Cisco ISE installation.
• Virtual Machine:
a. Map the CD/DVD to an ISO image. A screen similar to the following one appears. The following message and
installation menu are displayed.
Welcome to the Cisco Identity Services Engine Installer
Cisco ISE Version: [Link]
Step 4 At the boot prompt, press 1 and Enter to install Cisco ISE using a serial console.
If you want to use a keyboard and monitor, use the arrow key to select the Cisco ISE Installation (Keyboard/Monitor)
option. The following message appears.
**********************************************
Please type 'setup' to configure the appliance
**********************************************
Step 5 At the prompt, type setup to start the Setup program. See Run the Setup Program of Cisco ISE, on page 33 for details
about the Setup program parameters.
Step 6 After you enter the network configuration parameters in the Setup mode, the appliance automatically reboots, and returns
to the shell prompt mode.
Step 7 Exit from the shell prompt mode. The appliance comes up.
Step 8 Continue with Verifying the Cisco ISE Installation Process, on page 36 .
USB 1 hour -
The setup program launches an interactive command-line interface (CLI) that prompts you for the required
parameters. An administrator can use the console or a dumb terminal to configure the initial network settings
and provide the initial administrator credentials for the ISE server using the setup program. This setup process
is a one-time configuration task.
Note If you are integrating with Active Directory (AD), it is best to use the IP and subnet addresses from a dedicated
Site created specifically for ISE. Consult with the staff in your organization responsible for AD and retrieve
the relevant IP and subnet addresses for your ISE nodes prior to installation and configuration.
Note It is not recommended to attempt offline installation of Cisco ISE as this can lead to system instability. When
you run the Cisco ISE installation script offline, the following error is shown:
Sync with NTP server failed' Incorrect time could render the system unusable until it is re-installed.
Retry? Y/N [Y]:
Choose Yes to continue with the installation. Choose No to retry syncing with the NTP server.
It is recommended to establish network connectivity with both the NTP server and the DNS server while
running the installation script.
Procedure
(eth0) Ethernet Must be a valid IPv4 or Global IPv6 address for the Gigabit [Link]/ [Link]
interface address Ethernet 0 (eth0) interface.
Default gateway Must be a valid IPv4or Global IPv6 address for the default [Link]/ [Link]
gateway.
Primary name Must be a valid IPv4 or Global IPv6 address for the primary [Link] / [Link]
server name server.
Add/Edit another Must be a valid IPv4 or Global IPv6 address for the primary (Optional) Allows you to configure
name server name server. multiple name servers. To do so, enter y
to continue.
Primary NTP Must be a valid IPv4 or Global IPv6 address or hostname of [Link] / [Link] /
server a Network Time Protocol (NTP) server. [Link]
Note
Ensure that the primary NTP server is reachable.
Add/Edit another Must be a valid NTP domain. (Optional) Allows you to configure
NTP server multiple NTP servers. To do so, enter y to
continue.
System Time Zone Must be a valid time zone. For example, for Pacific Standard UTC (default)
Time (PST), the System Time Zone is PST8PDT (or
Coordinated Universal Time (UTC) minus 8 hours).
Note
Ensure that the system time and time zone match with the
CIMC or Hypervisor Host OS time and time zone. System
performance might be affected if there is any mismatch
between the time zones.
Note
We recommend that you set all the Cisco ISE nodes to the
UTC time zone. This time zone setting ensures that the
reports, logs, and posture agent log files from the various
nodes in your deployment are always synchronized with
regard to the time stamps.
Username Identifies the administrative username used for CLI access admin (default)
to the Cisco ISE system. If you choose not to use the default
(admin), you must create a new username. The username
must be three to eight characters in length and comprise of
valid alphanumeric characters (A–Z, a–z, or 0–9).
Password Identifies the administrative password that is used for CLI MyIseYPass2
access to the Cisco ISE system. You must create this password
in order to continue because there is no default password.
The password must be a minimum of six characters in length
and include at least one lowercase letter (a–z), one uppercase
letter (A–Z), and one numeral (0–9).
Note
When you create a password for the administrator during installation or after installation in the CLI, do not use the $
character in your password, unless it is the last character of the password. If it is the first or one of the subsequent characters,
the password is accepted, but cannot be used to log in to the CLI.
If you inadvertently create such a password, reset your password by logging into the console and using the CLI command,
or by getting an ISE CD or ISO file. Instructions for using an ISO file to reset the password are explained in the following
document: [Link]
[Link]
Procedure
Step 1 When the system reboots, at the login prompt enter the username you configured during setup, and press Enter.
Step 2 Enter a new password.
Step 3 Verify that the application has been installed properly by entering the show application command, and press Enter.
The console displays:
ise/admin# show application
<name> <Description>
ise Cisco Identity Services Engine
Note
The version and date might change for different versions of this release.
Step 4 Check the status of the ISE processes by entering the show application status ise command, and press Enter.
The console displays:
ise/admin# show application status ise
ise/admin#
Procedure
Step 11 Choose Cisco ISE Installation (Keyboard/Monitor) to proceed with the installation.
Note • Localized ISE Install option is supported for Cisco ISE 3.1 Patch 9 and later, Cisco ISE 3.2 Patch 5 and
later, Cisco ISE 3.3 Patch 2 and later, and Cisco ISE 3.4 and later releases.
• You can use this option to reinstall the current version and higher versions. You cannot install a version
that is older than the current version.
For more information, see "Localized ISE Installation" in the Chapter "Cisco ISE CLI Commands in EXEC
Mode" in the Cisco Identity Services Engine CLI Reference Guide.
Cisco ISE 3.1 Fedora LiveUSB-creator for SNS 3500/3600 series appliance
Rufus for SNS 3700 series appliance
Note Cisco ISE 3.1 patch 6 and later and Cisco ISE 3.2 patch 2 and later versions support Cisco SNS 3700 series
appliances.
Procedure
Step 1 Reformat the USB device using FAT16 or FAT32 to free up all the space.
Step 2 Plug in the USB device to the local system and launch Rufus.
Step 3 From the Boot Selection drop-down list, choose Disk or ISO Image.
Step 4 Click Select and choose the Cisco ISE ISO file.
Step 5 From the Partition Scheme drop-down list, choose MBR.
Step 6 From the Target System drop-down list, choose BIOS or UEFI.
Step 7 Click Start.
The progress bar indicates the progress of the bootable USB creation. After this process is complete, the content of the
USB drive is available in the local system that you used to run the USB tool.
Step 8 From the USB drive, open the following text files in a text editor:
• isolinux/[Link] or syslinux/[Link]
• EFI/BOOT/[Link]
Note
We recommend that you use Notepad as text editor to edit the configuration files. If you are using any other text editor
tool, ensure that the end of line (EOL) characters are set to "LF" (not "CR LF"). The installation via USB doesn't work
if EOL characters are set to "CR LF”.
Step 9 For SNS hardware appliance, replace the term "cdrom" with "hd:sdb1" in both the files.
Specifically, replace all instances of the "cdrom" string. For example, replace
ks=cdrom/[Link]
with
ks=hd:sdb1:/[Link]
Step 10 Open [Link] file and replace the term “cdrom” with “harddrive --partition=/dev/disk/by-label/ADEOS --dir=/”
Step 11 Save the files and exit.
Step 12 Safely remove the USB device from the local system.
Step 13 Plug in the bootable USB device to the Cisco ISE appliance, restart the appliance, and boot from the USB drive to
install Cisco ISE.
Note Cisco SNS hardware appliances support the Unified Extensible Firmware Interface (UEFI) secure boot feature.
This feature ensures that only a Cisco-signed ISE image can be installed on the SNS hardware appliances,
and prevents installation of any unsigned operating system even with physical access to the device. For
example, generic operating systems, such as Red Hat Enterprise Linux or Microsoft Windows cannot boot
on this appliance.
• Use the Cisco Integrated Management Controller (Cisco IMC) interface to map the installation .iso file
to the virtual DVD device.
• Create an install DVD with the installation .iso file and plug in an USB external DVD drive and boot
the appliance from the DVD drive.
• Create a bootable USB device using the installation .iso file and boot the appliance from the USB drive.
Note The VMware form factor instructions provided in this document are applicable for Cisco ISE installed on
Cisco Hyperflex as well.
When you run the Setup program, a VM performance check is done, where the installer checks for disk I/O
performance. If the disk I/O performance does not meet the recommended specifications, a warning appears
on screen, but it allows you to continue with the installation.
The VM performance check is done periodically (every hour) and the results are averaged for a day. If the
disk I/O performance does not meet the recommended specification, an alarm is generated.
The VM performance check can also be done on demand from the Cisco ISE CLI using the show tech-support
command.
The VM resource and performance checks can be run independent of Cisco ISE installation. You can perform
this test from the Cisco ISE boot menu.
Install Cisco ISE on VMware Virtual Machine Using the ISO File
This section describes how to install Cisco ISE on a VMware virtual machine using the ISO file.
If HV Support has a value of 3, then VT is enabled on the ESXi server and you can proceed with the installation.
If HV Support has a value of 2, then VT is supported, but not enabled on the ESXi server. You must edit the
BIOS settings and enable VT on the server.
Procedure
Configure VMware Server Interfaces for the Cisco ISE Profiler Service
Configure VMware server interfaces to support the collection of Switch Port Analyzer (SPAN) or mirrored
traffic to a dedicated probe interface for the Cisco ISE Profiler Service.
Procedure
Step 1 Choose Configuration > Networking > Properties > VMNetwork (the name of your VMware server
instance)VMswitch0 (one of your VMware ESXi server interfaces) Properties Security.
Step 2 In the Policy Exceptions pane on the Security tab, check the Promiscuous Mode check box.
Step 3 In the Promiscuous Mode drop-down list, choose Accept and click OK.
Repeat the same steps on the other VMware ESXi server interface used for profiler data collection of SPAN or mirrored
traffic.
Procedure
Step 1 Power down the particular VMware server (for example ISE-120).
Step 2 Right-click the VMware server and choose Edit.
Step 3 Click Add on the Hardware tab.
Step 4 Choose Serial Port and click Next.
Step 5 In the Serial Port Output area, click the Use physical serial port on the host or the Connect via Network radio button
and click Next.
• If you choose the Connect via Network option, you must open the firewall ports over the ESXi server.
• If you select the Use physical serial port on the host, choose the port. You may choose one of the following two
options:
• /dev/ttyS0 (In the DOS or Windows operating system, this will appear as COM1).
• /dev/ttyS1 (In the DOS or Windows operating system, this will appear as COM2).
Procedure
Step 5 In the Select a compute resource area, choose a destination compute resource and click Next.
Step 6 In the Select storage area, choose a datastore that has the recommended amount of space available and click Next.
Step 7 In the Select compatibility area, from the Compatible with drop-down list, choose an ESXi version that is compatible
with your Cisco ISE version and click Next.
For information the ESXi versions that are compatible with your Cisco ISE release, see "Supported Virtual Environments"
in the Release Notes for Cisco Identity Services Engine for your release.
Step 8 In the Select a guest OS area, carry out the following steps and then click Next:
a. From the Guest OS Family drop-down list, choose Linux.
b. From the Guest OS Version drop-down list, choose the supported Red Hat Enterprise Linux (RHEL) version.
Cisco ISE Release 3.1 and later use RHEL 8.
Step 9 In the Customize hardware area, in the Virtual Hardware tab, carry out the following configurations and then click
Next.
a. choose the required values from the CPU and Memory drop-down lists according to the SNS series appliance you
use:
SNS 3600 Series Appliance:
• Small—16 vCPU cores, 32 GB
• Medium—24 vCPU cores, 96 GB
• Large—24 vCPU cores, 256 GB
The number of cores is twice of that present in equivalent of the Cisco Secure Network Server 3600 series,
due to hyperthreading. For example, in case of Small network deployment, you must allocate 16 vCPU cores
to meet the CPU specification of SNS 3615, which has 8 CPU Cores or 16 Threads.
Note
You must reserve vCPU and memory resources equivalent to the configured vCPU cores and memory allocations.
Failure to do so may significantly impact Cisco ISE performance and stability. Click the CPU and Memory
collapsible areas and update the reservation fields for each setting.
Step 10 Choose the NIC driver from the Adapter drop-down list and click Next.
Step 11 Choose Create a new virtual disk and click Next.
Step 12 In the Disk Provisioning dialog box, click Thick provisioned, eagerly zeroed radio button, and click Next to continue.
Cisco ISE supports both thick and thin provisioning. However, we recommend that you choose thick provisioned,
eagerly zeroed for better performance, especially for Monitoring nodes. If you choose thin provisioning, operations
such as upgrade, backup and restore, and debug logging that require more disk space might be impacted during initial
disk expansion.
Step 13 Uncheck the Support clustering features such as Fault Tolerance check box.
Step 14 In the Ready to complete area, verify the configuration details, such as name, guest OS, CPUs, memory, and disk size
of the newly created VMware system.
Step 15 Click Finish.
The VMware system is now installed.
What to do next
To activate the newly created VMware system, right-click VM in the left pane of your VMware client user
interface and choose Power > Power On.
Procedure
Step 1 From the VSphere client, right click the VM and choose Edit Settings.
Step 2 Click the Options tab.
Step 3 Choose Advanced > Boot Options.
Step 4 From the Power on Boot Delay area, select the time in milliseconds to delay the boot operation.
Step 5 Check the check box in the Force BIOS Setup area to enter into the BIOS setup screen when the VM boots the next
time.
Step 6 Click OK to save your changes.
Procedure
If you have selected Guest OS RHEL 8 and EFI boot mode, disable the Enable UEFI Secure Boot option. This option
is enabled by default for Guest operating system RHEL 8 VM.
Step 8 Use the arrow keys to select Cisco ISE Installation (Serial Console) or Cisco ISE Installation (Keyboard/Monitor)
and press Enter. If you choose the serial console option, you should have a serial console set up on your virtual machine.
See the VMware vSphere Documentation for information on how to create a console.
The installer starts the installation of the Cisco ISE software on the VMware system. Allow 20 minutes for the installation
process to complete. When the installation process finishes, the virtual machine reboots automatically. When the VM
reboots, the console displays:
Type 'setup' to configure your appliance
localhost:
The Setup Wizard appears and guides you through the initial configuration.
Note For cloning, you need VMware vCenter. Cloning must be done before you run the Setup program.
Procedure
Step 1 Log in to the ESXi server as a user with administrative privileges (root user).
VMware vCenter is required to perform this step.
Step 2 Right-click the Cisco ISE VM you want to clone, and click Clone.
Step 3 Enter a name for the new machine that you are creating in the Name and Location dialog box and click Next.
This is not the hostname of the new Cisco ISE VM that you are creating, but a descriptive name for your reference.
Step 4 Select a Host or Cluster on which you want to run the new Cisco ISE VM and click Next.
Step 5 Select a datastore for the new Cisco ISE VM that you are creating and click Next.
This datastore could be the local datastore on the ESXi server or a remote storage. Ensure that the datastore has enough
disk space.
Step 6 Click the Same format as source radio button in the Disk Format dialog box and click Next.
This option copies the same format that is used in the Cisco ISE VM that you are cloning this new machine from.
Step 7 Click the Do not customize radio button in the Guest Customization dialog box and click Next.
Step 8 Click Finish.
What to do next
• Changing the IP Address and Hostname of a Cloned Virtual Machine
• Connecting a Cloned Cisco Virtual Machine to the Network
Note For cloning, you need VMware vCenter. Cloning must be done before you run the Setup program.
Procedure
Procedure
Step 1 Log in to the ESXi server as a user with administrative privileges (root user).
VMware vCenter is required to perform this step.
Step 2 Right-click the Cisco ISE VM that you want to clone and choose Clone > Clone to Template.
Step 3 Enter a name for the template, choose a location to save the template in the Name and Location dialog box, and click
Next.
Step 4 Choose the ESXi host that you want to store the template on and click Next.
Step 5 Choose the datastore that you want to use to store the template and click Next.
Ensure that this datastore has the required amount of disk space.
Step 6 Click the Same format as source radio button in the Disk Format dialog box and click Next.
The Ready to Complete dialog box appears.
Procedure
Step 1 Right-click the Cisco ISE VM template that you have created and choose Deploy Virtual Machine from this template.
Step 2 Enter a name for the new Cisco ISE node, choose a location for the node in the Name and Location dialog box, and click
Next.
Step 3 Choose the ESXi host where you want to store the new Cisco ISE node and click Next.
Step 4 Choose the datastore that you want to use for the new Cisco ISE node and click Next.
Ensure that this datastore has the required amount of disk space.
Step 5 Click the Same format as source radio button in the Disk Format dialog box and click Next.
Step 6 Click the Do not customize radio button in the Guest Customization dialog box.
The Ready to Complete dialog box appears.
Step 7 Check the Edit Virtual Hardware check box and click Continue.
The Virtual Machine Properties page appears.
Step 8 Choose Network adapter, uncheck the Connected and Connect at power on check boxes, and click OK.
Step 9 Click Finish.
You can now power on this Cisco ISE node, configure the IP address and hostname, and connect it to the network.
What to do next
• Change the IP Address and Hostname of a Cloned Virtual Machine
• Connect a Cloned Cisco Virtual Machine to the Network
• Ensure that you have the IP address and hostname that you are going to configure for the newly cloned
VM as soon as you power on the machine. This IP address and hostname entry should be in the DNS
server. You cannot use "localhost" as the hostname for a node.
• Ensure that you have certificates for the Cisco ISE nodes based on the new IP address or hostname.
Procedure
Procedure
Step 1 Right-click the newly cloned Cisco ISE VM and choose Power > Power On.
Step 2 Select the newly cloned Cisco ISE VM and click the Console tab.
Step 3 Enter the following commands on the Cisco ISE CLI:
configure terminal
hostname hostname
The hostname is the new hostname that you are going to configure. The Cisco ISE services are restarted.
The ip_address is the address that corresponds to the hostname that you entered in step 3 and netmask is the subnet mask
of the ip_address. The system will prompt you to restart the Cisco ISE services. See the Cisco Identity Services Engine
CLI Reference Guide, for the ip address and hostname commands.
Procedure
Step 1 Right-click the newly cloned Cisco ISE virtual machine (VM) and click Edit Settings.
Step 2 Click Network adapter in the Virtual Machine Properties dialog box.
Step 3 In the Device Status area, check the Connected and Connect at power on check boxes.
Step 4 Click OK.
Procedure
Virtual Machine Resource Check from the Cisco ISE Boot Menu
You can check for virtual machine resources independent of Cisco ISE installation from the boot menu.
The CLI transcript appears as follows:
Use the arrow keys to select System Utilities (Serial Console) or System Utilities (Keyboard/Monitor) and
press Enter. The following screen appears:
Enter 2 to check for VM resources. The output will be similar to the following:
*****
***** Virtual Machine host detected…
***** Hard disk(s) total size detected: 600 Gigabyte
***** Physical RAM size detected: 16267516 Kbytes
***** Number of network interfaces detected: 6
***** Number of CPU cores: 12
***** CPU Mhz: 2300.00
***** Verifying CPU requirement…
Linux KVM
KVM Virtualization Check
KVM virtualization requires virtualization support from the host processor; Intel VT-x for Intel processors
and AMD-V for AMD processors. Open a terminal window on the host and enter the cat /proc/cpuinfo
command. You must see either the vmx or the svm flag.
• For Intel VT-x:
# cat /proc/cpuinfo
flags: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush
dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx
pdpe1gb rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology nonstop_tsc
aperfmperf eagerfpu pni pclmulqdq dtes64 monitor
ds_cpl vmx smx est tm2 ssse3 cx16 xtpr pdcm pcid dca sse4_1 sse4_2 x2apic popcnt
tsc_deadline_timer aes xsave avx lahf_lm arat epb xsaveopt
pln pts dtherm tpr_shadow vnmi flexpriority ept vpid
• For AMD-V:
# cat /proc/cpuinfo
flags: fpu tsc msr pae mce cx8 apic mtrr mca cmov pat pse36 clflush mmx fxsr sse sse2
ht syscall nx mmxext fxsr_opt rdtscp lm 3dnowext 3dnow
pni cx16 lahf_lm cmp_legacy svm cr8_legacy
Procedure
Step 2 Click Local install media (ISO media or CDROM), and then click Forward.
Step 3 Click the Use ISO image radio button, click Browse, and select the ISO image from your local system.
a) Uncheck the Automatically detect operating system based on install media check box, choose Linux as the OS
type, choose supported Red Hat Enterprise Linux version, and click Forward.
Step 4 Choose the RAM and CPU settings and click Forward.
Step 5 Check the Enable storage for this virtual machine check box and choose the storage settings.
a) Click the Select managed or other existing storage radio button.
b) Click Browse.
c) From the Storage Pools navigation pane on the left, click disk FileSystem Directory.
d) Click New Volume.
A Create storage volume window appears.
e) Enter a name for the storage volume.
f) Choose raw from the Format drop-down list.
g) Enter the Maximum Capacity.
h) Click Finish.
i) Choose the volume that you created and click Choose Volume.
j) Click Forward.
The Ready to begin the installation screen appears.
IO mode native
Note You must add the following text to the VM settings XML file (under vcpu information) while installing Cisco
ISE on Ubuntu Linux KVM. Otherwise, serial number will not be properly displayed in the About ISE and
Server window:
<sysinfo type="smbios">
<system>
<entry name="product">KVM</entry>
</system>
<baseBoard>
<entry name="product">KVM</entry>
</baseBoard>
</sysinfo>
<OS>
<type arch="x86_64" machine="pc-q35-6.2">hvm</type>
<boot dev="hd"/>
<smbios mode="sysinfo"/>
</os>
Microsoft Hyper-V
Note Cisco ISE does not support the use of Multipath I/O (MPIO). Hence, the installation will fail if you are using
MPIO for the VM.
Procedure
Step 2 Right-click the VM host and click New > Virtual Machine.
Step 4 Enter a name for the VM and (optionally) choose a different path to store the VM, and click Next.
Step 6 Specify the amount of memory to allocate to this VM, for example, 16000 MB, and click Next.
Step 8 Click the Create a virtual hard disk radio button and click Next.
Step 9 Click the Install an operating system from a bootable CD/DVD-ROM radio button.
a) From the Media area, click the Image file (.iso) radio button.
b) Click Browse to select the ISE ISO image from the local system and click Next.
Step 12 Select the VM and click Connect to launch the VM console. Click the start button to turn on the Cisco ISE VM.
Note You cannot use an .img file for ZTP on Microsoft Hyper-V. You must use an
.iso file and create a Generation 2 VM for ZTP on Microsoft Hyper-V.
• VM User Data: This method is supported in OVA and VM automatic installations. It is supported when
the user data is configured and requires mandatory parameters such as hostname, IP address, IP netmask,
IP default gateway, DNS domain, primary name server, NTP server, system timezone, SSH, username,
and password to be configured. Optional parameters such as IPV6, patch, hot patch, services, and repository
details can also be configured. For more information, see VM User Data.
Note • To track installation progress during the ZTP process, the serial console should be enabled for both the
VM and the appliance.
• A ZTP Configuration Image File is required.
If you provision Cisco ISE through ZTP, the following two security features are available:
• Configure Public Key Authentication
• First Login Password Change
Note TFTP, HTTP, HTTPS, and NFS repositories are supported for installation of hot patches and patches on Cisco
ISE as part of the ZTP flow. The repositories created during the ZTP flow will not be visible or usable from
the Cisco ISE GUI. These repositories must have anonymous access (no username/password) for the ZTP
process to use them.
To revert back to password-based authentication use the following command in the Cisco ISE CLI:
conf t
no service sshd PubkeyAuthentication
For more information about this command, see the section "Service" in the Chapter "Cisco ISE CLI Commands
in Configuration Mode" in the Cisco Identity Services Engine CLI Reference Guide for your Cisco ISE release.
Note Do not execute the command service sshd PubkeyAuthentication if you have not included the public key
in the ZTP configuration image file before installation. This disables password-based authentication and Cisco
ISE will expect you to login using a private key. If you do run into this issue, you need to use the console port
to login into Cisco ISE and revert the configuration.
Procedure
Step 1 Generate a public and private RSA key pair using a third-party application.
Step 2 Include the public key that is generated in the Creating the ZTP Configuration Image File.
Step 3 Install Cisco ISE using ZTP.
Step 4 Log in to the CLI of Cisco ISE using the private key that is generated, using the following command:
ssh -i <path to private key> <username>@<ise-ip>
You can now successfully log in to the CLI of Cisco ISE using your private key.
Automatic Installation in Virtual Machine Using the ZTP Configuration Image File
Procedure
Step 2 For the VM to enter the BIOS setup mode, right-click the VM and select Edit Settings.
Step 3 Click the Options tab.
Step 4 Click Boot Options.
Step 5 In the Force BIOS Setup area, check the BIOS check box to enter the BIOS setup screen when the VM boots.
Note
You must change the firmware from BIOS to EFI in the the boot mode of VM settings in order to boot GPT partitions
with 2 TB or more capacity.
Note
From Cisco ISE 3.1 onwards, pressing Enter without entering a boot option does not trigger the installation using the
hard disk option. Instead it triggers ZTP.
Step 11 After 150 seconds, the bootup process automatically starts if the prerequisites are met.
Note
• Installation logs can be monitored only through the serial console because ZTP only works through the serial
console. It can be monitored from the VM console after the setup prompt is displayed.
• After the Cisco ISE services are started, you must manually unmount the ZTP configuration image file from the
CD/DVD.
To leverage ZTP from the setup prompt (ZTP is carried out using the keyboard until the setup prompt apprears) perform
this procedure:
1. Install Cisco ISE manually till setup (using boot option 1 or 2) and create the ZTP configuration image file using the
steps described in the above procedure.
2. Power off the VM and map the ZTP configuration image file to the CD/DVD drive.
3. Power on the VM.
The setup details are picked up from the ZTP configuration file that is mapped to the CD/DVD drive.
Troubleshooting
Issue: If the automatic installation in the VM is triggered without mapping the .img file, after 150 seconds,
the installation fails with the following message:
***** The ZTP configuration image is missing or improper. Automatic installation flow
exited.
***** Power off and attach the proper ZTP configuration image or choose manual boot to
proceed.
Solution: This error message is seen only through the serial console and not on the VM console. If this happens
in an existing VM where Cisco ISE is already installed, the hard disk will not be formatted at this state. The
existing VM can be recovered by performing these steps: :
1. Turning off the VM.
2. Turning on the VM.
3. Pressing option 5 to boot from hard disk within 150 seconds to load the existing VM.
Issue: If the setup details are invalid in the configuration file, ZTP installation is stopped and the following
message is displayed on the VM Console:
==============================================================================
==============================================================================
Check the setup details in your configuration image and reboot Cisco ISE
==============================================================================
Solution:
1. Create a new configuration .img file with valid details.
2. Power off the VM.
3. Map the new valid image to the CD/DVD drive.
4. Power on the VM.
Installation begins from the setup.
Procedure
Step 2 For the VM to enter the BIOS setup mode, right-click the VM and select Edit Settings.
Step 3 Click the Options tab.
Step 4 Click Boot Options.
Step 5 In the Force BIOS Setup area, check the BIOS check box to enter the BIOS setup screen when the VM boots.
Note
You must change the firmware from BIOS to EFI in the the boot mode of VM settings in order to boot GPT partitions
with 2 TB or more capacity.
Note
From Cisco ISE 3.1 onwards, pressing Enter without entering a boot option does not trigger the installation using the
hard disk option. Instead it triggers ZTP.
Step 11 After 150 seconds, the bootup process automatically starts if the prerequisites are met.
Note
• Installation logs can be monitored only through the serial console because ZTP works only through the serial
console. It can be monitored from the VM console after the setup prompt is displayed.
• After the Cisco ISE services are started, you must manually unmount the ZTP configuration image file from the
CD/DVD.
To leverage ZTP from the setup prompt (ZTP is carried out using the keyboard until the setup prompt apprears) perform
this procedure:
1. Power off the VM.
2. Configure user-data option mentioned above.
3. Power on the VM .
The setup details are picked from the VM options.
Troubleshooting
Issue: If invalid setup details are entered in the user data option, the ZTP installation stops and the following
message is displayed on the VM console:
==============================================================================
==============================================================================
Check the setup details in your configuration image and reboot Cisco ISE
==============================================================================
Solution:
1. Power off the VM.
2. Update user data details with valid data.
3. Power on the VM.
Installation begins from the setup.
Procedure
Step 6 After 150 seconds, the start process automatically starts if the prerequisites are met.
Note
• ZTP works on the SNS appliance through virtual media only.
• You must map the .img file in virtual media before mapping the ISO file.
Installation logs can be monitored through only the serial console because ZTP works through the serial console.
The logs can be monitored from the KVM console after the setup prompt is displayed.
• Automatic installation in appliance is supported only with the .img file.
To leverage ZTP from the setup prompt (ZTP is done using the keyboard until the setup prompt apprears) perform the
following steps:
1. Install Cisco ISE manually till setup (using boot option 1 or 2) and create the ZTP configuration image file using the
steps described in the previous above.
2. Power off the host and map the ZTP configuration image file that is created, to the CD/DVD drive.
3. Power on the host.
The setup details are picked from the ZTP configuration file that is mapped to the CD/DVD drive.
Troubleshooting
Issue: If the automatic installation in the appliance is triggered without mapping the image file, after 150
seconds, the installation fails with the following message:
***** The ZTP configuration image is missing or improper. Automatic installation flow
exited.
***** Power off and attach the proper ZTP configuration image or choose manual boot to
proceed.
Solution:
1. Turn off the VM.
2. Turn on the VM.
3. Press option 5 to boot from hard disk within 150 seconds to load the existing VM.
Issue: If the setup details are invalid in the config file, ZTP installation is stopped and the following message
is displayed on the KVM console:
==============================================================================
==============================================================================
Check the setup details in your configuration image and reboot Cisco ISE
==============================================================================
Solution:
1. Create a new configuration .img file with valid details.
2. Power off the VM.
3. Map the new valid image to the CD/DVD drive.
4. Power on the VM.
Installation begins from the setup.
Note The API URL and the request header are the same for all the methods:
API URL
[Link]
Header
headers["Accept"] = "application/xml"
headers["Content-Type"] = "application/xml"
Procedure
Response
<aaaLogin cookie="" response="yes" outCookie="<real_cookie>" outRefreshPeriod="600" outPriv="admin"
outSessionId="17" outVersion="3.0(0.149)"> </aaaLogin>
Response
<configConfMo dn="sys/svc-ext/vmedia-svc/vmmap-ISE_ISO"
cookie="<real_cookie>" response="yes">
<outConfig>
<commVMediaMap volumeName="ISE_ISO" map=“nfs”
remoteShare=‘<nfs_server_path>'
remoteFile="<ise_iso_file>"
mappingStatus="In Progress"
dn="sys/svc-ext/vmedia-svc/vmmap-ISE_ISO" status="created"/>
</outConfig>
</configConfMo>
Request
<configConfMo cookie='<real_cookie>'
dn='sys/svc-ext/vmedia-svc/vmmap-CONFIG-IMG’ inHierarchical='false'>
<inConfig>
<commVMediaMap dn='sys/svc-ext/vmedia-svc/vmmap-CONFIG-IMG'
map=’nfs’
remoteFile=‘<config_img_file>’
remoteShare=‘<nfs_server_path>'
status='created' volumeName='CONFIG-IMG' />
</inConfig>
</configConfMo>
Response
<configConfMo dn="sys/svc-ext/vmedia-svc/vmmap-CONFIG-IMG"
cookie="<real_cookie>" response="yes">
<outConfig>
<commVMediaMap volumeName="CONFIG-IMG" map=“nfs”
remoteShare=‘<nfs_server_path>'
remoteFile="<config_img_file>"
mappingStatus="In Progress"
dn="sys/svc-ext/vmedia-svc/vmmap-CONFIG-IMG" status="created"/>
</outConfig>
</configConfMo>
</lsbootDef>
</inConfig>
</configConfMo>
Response
<configConfMo dn="sys/rack-unit-1/boot-policy" cookie="<real_cookie>" response="yes">
<outConfig>
<lsbootDef dn="sys/rack-unit-1/boot-policy" name="boot-policy" purpose="operational"
rebootOnUpdate="no" status="modified" >
</lsbootDef>
</outConfig>
</configConfMo>
Response
Response
<configConfMo dn="sys/rack-unit-1" cookie="<real_cookie>" response="yes">
<outConfig>
<computeRackUnit dn="sys/rack-unit-1" adminPower="policy" availableMemory="262144"
model="SNS-3695-K9" memorySpeed="2400" name="SNS-3695-K9" numOfAdaptors="0" numOfCores="12"
numOfCoresEnabled="12" numOfCpus="1" numOfEthHostIfs="0" numOfFcHostIfs="0" numOfThreads="24"
operPower="on" originalUuid="1935836B-B968-4031-8A98-7984F1D35449" presence="equipped" serverId="1"
serial="WZP2228085W" totalMemory="262144" usrLbl="" uuid="1935836B-B968-4031-8A98-7984F1D35449"
vendor="Cisco Systems Inc" cimcResetReason="graceful-reboot
" assetTag="Unknown" adaptorSecureUpdate="Enabled" resetComponents="components" storageResetStatus="NA"
vicResetStatus="NA" bmcResetStatus="NA" smartUsbAccess="disabled" smartUsbStatus="Disabled"
biosPostState="completed" status="modified" >
</computeRackUnit>
</outConfig>
</configConfMo>
Response:
<aaaLogout cookie="" response="yes" outStatus="success"> </aaaLogout>
Procedure
Step 2 For the VM to enter the BIOS setup mode, right-click the VM and select Edit Settings.
Step 3 Click the Options tab.
Step 4 Click Boot Options.
Step 5 In the Force BIOS Setup area, check the BIOS check box to enter the BIOS setup screen when the VM boots.
Note
You must change the firmware from BIOS to EFI in the the boot mode of VM settings in order to boot GPT partitions
with 2 TB or more capacity.
Note
From Cisco ISE 3.1 onwards, pressing Enter without entering a boot option does not trigger the installation using the
hard disk option. Instead it triggers ZTP.
Step 11 After 150 seconds, the bootup process automatically starts if the prerequisites are met.
Note
• Installation logs can be monitored only through the serial console because ZTP works only through the serial
console. The logs can be monitored from the VM console after the setup prompt is displayed.
• After the Cisco ISE services are started, you must manually unmount the ZTP configuration image file from the
CD/DVD.
To leverage ZTP from the setup prompt (ZTP is done using the keyboard until the setup prompt apprears) perform this
procedure:
1. Install Cisco ISE manually till setup (using boot option 1 or 2) and create the ZTP configuration image file using the
steps described in the above procedure.
2. Power off the VM.
3. Map the ZTP configuration image file to the CD/DVD drive.
4. Power on the VM.
The setup details are picked up from the ZTP configuration file that is mapped to the CD/DVD drive.
Troubleshooting
Issue: If the setup details are invalid in the configuration file, ZTP installation stops and the following message
is displayed on the VM console:
==============================================================================
==============================================================================
Check the setup details in your configuration image and reboot Cisco ISE
==============================================================================
Procedure
Step 2 For the VM to enter the BIOS setup mode, right-click the VM and select Edit Settings.
Step 3 Click the Options tab.
Step 4 Click Boot Options.
Step 5 In the Force BIOS Setup area, check the BIOS check box to enter the BIOS setup screen when the VM boots.
Note
You must change the firmware from BIOS to EFI in the the boot mode of VM settings in order to boot GPT partitions
with 2 TB or more capacity.
Note
From Cisco ISE 3.1 onwards, pressing Enter without entering a boot option does not trigger the installation using the
hard disk option. Instead it triggers ZTP.
Step 11 After 150 seconds, the bootup process automatically starts if the prerequisites are met.
Note
• Installation logs can be monitored only through the serial console because ZTP works only through the serial
console. It can be monitored from the VM console after the setup prompt is displayed.
• After the Cisco ISE services are started, you must manually unmount the ZTP configuration image file from the
CD/DVD.
To leverage ZTP from the setup prompt (ZTP is carried out using the keyboard until the setup prompt apprears) perform
this procedure:
1. Power off the VM.
2. Configure user-data option mentioned above.
3. Power on the VM .
The setup details are picked from the VM options.
Troubleshooting
Issue: If invalid setup details are entered in the user data option, the ZTP installation stops and the following
message is displayed on the VM console:
==============================================================================
==============================================================================
Check the setup details in your configuration image and reboot Cisco ISE
==============================================================================
Note The default values for these flags is false which means by default, during the ZTP installation the above checks
will be made if not explicitly mentioned in the configuration file.
cp $conf_file $mountpath/[Link]
sync
umount $mountpath
sleep 1
# Check for automount and unmount
automountpath=$(mount | grep $ztplabel | awk '{print $3}')
if [ -n "$automountpath" ];then
umount $automountpath
fi
echo "Image created $image"
VM User Data
VM user data is supported from ESXi 6.5 and later for Cisco ISE installation.
Paste the content of the [Link] file in the base64encode tool. Use the base64encode tool to get the
encoded string.
You have to enter the encoded base64 string in the VM along with the VM user data. In the VMware ESXi,
go to VM Options > Advanced > Configuration Parameters > Edit Configuration > [Link] =
[Value] Base Encoded ZTP Configuration to enter the string.
Note While configuring ZTP for deploying a patch or hot patch, you must use http (lower case) instead of HTTP.
Otherwise, the patch files cannot be downloaded from the repository.
Note We recommend that you use the Cisco ISE user interface to periodically reset your administrator login
password.
Caution For security reasons, we recommend that you log out when you complete your administrative session. If you
do not log out, the Cisco ISE web-based web interface logs you out after 30 minutes of inactivity, and does
not save any unsubmitted configuration data.
For information about the validated browsers, see "Validated Browsers" section in the Cisco ISE Release
Notes.
Note If Cisco ISE is installed in the cloud or using the ZTP process, you will be prompted to change the web-based
admin user password during the first login.
Procedure
Step 1 After the Cisco ISE appliance reboot has completed, launch one of the supported web browsers.
Step 2 In the Address field, enter the IP address (or hostname) of the Cisco ISE appliance by using the following format and
press Enter.
Step 3 Enter a username and password that you defined during setup.
Step 4 Click Login.
CLI-Admin only • Start and stop the Cisco ISE application software.
• Reload or shut down the Cisco ISE appliance.
• Reset the web-based admin user in case of a lockout.
• Access the ISE CLI.
Procedure
Step 2 Specify and confirm a new password that is different from the previous two passwords that were used for this administrator
ID:
Note A CLI-admin user and a web-based admin user credentials are different in Cisco ISE.
Procedure
Step 1 After the Cisco ISE appliance reboot has completed, launch one of the supported web browsers.
Step 2 In the Address field, enter the IP address (or host name) of the Cisco ISE appliance using the following format and
press Enter.
Step 3 In the Cisco ISE Login page, enter the username and password that you have defined during setup and click Login.
For example, entering [Link] displays the Cisco ISE Login page.
Note
For first-time web-based access to Cisco ISE system, the administrator username and password is the same as the CLI-based
access that you configured during setup.
Step 4 Use the Cisco ISE dashboard to verify that the appliance is working correctly.
What to do next
By using the Cisco ISE web-based user interface menus and options, you can configure the Cisco ISE system
to suit your needs. For details on configuring Cisco ISE, see Cisco Identity Services Engine Administrator
Guide.
Procedure
Step 1 After the Cisco ISE appliance reboot has completed, launch a supported product, such as PuTTY, for establishing a Secure
Shell (SSH) connection to a Cisco ISE appliance.
Step 2 In the Host Name (or IP Address) field, enter the hostname (or the IP address in dotted decimal format of the Cisco ISE
appliance) and click Open.
Step 3 At the login prompt, enter the CLI-admin username (admin is the default) that you configured during setup and press Enter.
Step 4 At the password prompt, enter the CLI-admin password that you configured during setup (this is user-defined and there
is no default) and press Enter.
Step 5 At the system prompt, enter show application version ise and press Enter.
Step 6 To check the status of the Cisco ISE processes, enter show application status ise and press Enter.
The console output appears as shown below:
ise-server/admin# show application status ise
ISE PROCESS NAME STATE PROCESS ID
--------------------------------------------------------------------
Database Listener running 4930
Database Server running 66 PROCESSES
Application Server running 8231
Profiler Database running 6022
ISE Indexing Engine running 8634
AD Connector running 9485
M&T Session Database running 3059
M&T Log Collector running 9271
M&T Log Processor running 9129
Certificate Authority Service running 8968
EST Service running 18887
SXP Engine Service disabled
TC-NAC Docker Service disabled
TC-NAC MongoDB Container disabled
TC-NAC RabbitMQ Container disabled
TC-NAC Core Engine Container disabled
VA Database disabled
VA Service disabled
pxGrid Infrastructure Service disabled
pxGrid Publisher Subscriber Service disabled
pxGrid Connection Manager disabled
pxGrid Controller disabled
PassiveID Service disabled
DHCP Server (dhcpd) disabled
DNS Server (named) disabled
Apply the latest patches, if any See the section "Software Patch Installation
Guidelines" in Chapter "Maintain and Monitor" in the
Cisco ISE Administrator Guide for your release.
Install Licenses See the Cisco ISE Licensing Guide for more
information. See Chapter "Licensing" in the Cisco
ISE Administrator Guide for your release.
Create Repository for Backups See the section "Create Repositories" in Chapter
"Maintain and Monitor" in the Cisco ISE
Administrator Guide for your release
Deploy Cisco ISE personas See the section "Cisco ISE Distributed Deployment"
in Chapter "Deployment" in the Cisco ISE
Administrator Guide for your release.
When two interfaces are bonded, one of the interfaces becomes the primary interface and the other becomes
the backup interface. When two interfaces are bonded, all traffic normally flows through the primary interface.
If the primary interface fails for some reason, the backup interface takes over and handles all the traffic. The
bond takes the IP address and MAC address of the primary interface.
When you configure the NIC bonding feature, Cisco ISE pairs fixed physical NICs to form bonded NICs.
The following table outlines which NICs can be bonded together to form a bonded interface.
Cisco ISE Physical NIC Linux Physical NIC Name Role in Bonded NIC Bonded NIC Name
Name
Supported Platforms
The NIC bonding feature is supported on all supported platforms and node personas. The supported platforms
include:
• SNS hardware appliances - Bond 0, 1, and 2
• VMware virtual machines - Bond 0, 1, and 2 (if six NICs are available to the virtual machine)
• Linux KVM nodes - Bond 0, 1, and 2 (if six NICs are available to the virtual machine)
• When you remove the bond between two interfaces, the IP address assigned to the bonded interface is
assigned back to the primary interface.
• If you want to configure the NIC bonding feature on a Cisco ISE node that is part of a deployment, you
must deregister the node from the deployment, configure NIC bonding, and then register the node back
to the deployment.
• If a physical interface that acts as a primary interface in a bond (Eth0, Eth2, or Eth4 interface) has static
route configured, the static routes are automatically updated to operate on the bonded interface instead
of the physical interface.
Procedure
% Warning: IP address of interface eth1 will be removed once NIC bonding is enabled. Are you sure
you want to proceed? Y/N [N]:
!
interface GigabitEthernet 0
ipv6 address autoconfig
ipv6 enable
backup interface GigabitEthernet 1
ip address [Link] [Link]
!
In the output above, "backup interface GigabitEthernet 1" indicates that NIC bonding is configured on Gigabit
Ethernet 0, with Gigabit Ethernet 0 being the primary interface and Gigabit Ethernet 1 being the backup
interface. Also, the ADE-OS configuration does not display an IP address on the backup interface in the
running config, even though the primary and backup interfaces effectively have the same IP address.
You can also run the show interface command to see the bonded interfaces.
GigabitEthernet 0
flags=6211<UP,BROADCAST,RUNNING,SUBORDINATE,MULTICAST> mtu 1500
ether [Link] txqueuelen 1000 (Ethernet)
RX packets 1726027 bytes 307336369 (293.0 MiB)
RX errors 0 dropped 844 overruns 0 frame 0
TX packets 1295620 bytes 1073397536 (1023.6 MiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
GigabitEthernet 1
flags=6211<UP,BROADCAST,RUNNING,SUBORDINATE,MULTICAST> mtu 1500
ether [Link] txqueuelen 1000 (Ethernet)
RX packets 0 bytes 0 (0.0 B)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 0 bytes 0 (0.0 B)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
device memory 0xfaa00000-faafffff
Procedure
Procedure
saving changes, enter [q] to Quit and return to the utilities menu.
[1]:admin
[2]:admin2
[3]:admin3
[4]:admin4
Password:
Verify password:
Step 5 Enter the number corresponding to the admin user whose password you want to reset.
Step 6 Enter the new password and verify it.
Step 7 Enter Y to save the changes.
Procedure
Step 2 Specify and confirm a new password that is different from the previous two passwords that were used for this administrator
ID:
Procedure
Procedure
ise/admin#
Procedure
Step 5 Enter Y.
The console prompts you with another warning:
THIS IS YOUR LAST CHANGE TO CANCEL. PROCEED WITH SYSTEM ERASE? [Y/N] Y
After you perform a system erase, if you want to reuse the appliance, you must boot the system using the Cisco ISE DVD
and choose the install option from the boot menu.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces
(Gigbit Ethernet 1 through 5, or Bond
1 and 2)
Related Concepts
Node Types and Personas in Distributed Deployments, on page 3
Note TCP keep alive time on ISE is 60 minutes. Adjust the TCP timeout values accordingly on the firewall if one
exists between ISE nodes.
1 3 4 6 7 9 13 17 19
20 21 22 23 24 25 26 30 32
33 37 42 43 49 53 70 79 80
81 82 83 84 85 88 89 90 99
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces
(Gigbit Ethernet 1 through 5, or Bond
1 and 2)
Note
Port 443 support Admin web applications
and are enabled by default.
HTTPS and SSH access to Cisco ISE is
restricted to Gigabit Ethernet 0.
TCP/9300 must be open on both Primary
and Secondary Administration Nodes for
incoming traffic.
Note
For SAML admin login, Port 8443 of PSN
should be reachable from the device where
the admin is trying to do the SAML login.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces
(Gigbit Ethernet 1 through 5, or Bond
1 and 2)
Note
This port is route table dependent.
• ICMP
Note
Default ports are configurable for external logging.
• WMI : TCP/135
• ODBC:
Note
The ODBC ports are configurable on the third-party database server.
Note
• For external identity sources and services reachable only through an interface
other than Gigabit Ethernet 0, configure static routes accordingly.
• Cisco ISE performs an ICMP ping towards DNS while diagnosing the
connection against an Active Directory connection.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces
(Gigbit Ethernet 1 through 5, or Bond
1 and 2)
Email Guest account and user password expirations email notification: SMTP: TCP/25
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond Ports on Other Ethernet Interfaces
0 (Gigabit Ethernet 1 through 5, or
Bond 1 and Bond 2)
• ICMP
Note
Default ports are configurable for external logging.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond Ports on Other Ethernet Interfaces
0 (Gigabit Ethernet 1 through 5, or
Bond 1 and Bond 2)
External Identity Sources and • Admin User Interface and Endpoint Authentications:
Resources (Outbound)
• LDAP: TCP/389, 3268, UDP/389
• SMB: TCP/445
• KDC: TCP/88, UDP/88
• KPASS: TCP/464
• WMI : TCP/135
• ODBC:
Note
The ODBC ports are configurable on the third-party database
server.
Note
For external identity sources and services reachable only through an
interface other than Gigabit Ethernet 0, configure static routes
accordingly.
Ports used for inbound • MnT inbound communication from an ISE node with the ISE API
communication Gateway enabled to route the MnT REST APIs: TCP/9443
• TCP/1521: Port 1521 must be enabled for the MnT nodes. Port
1521 is required for inbound communication from PAN. If this
port is not enabled for the MnT nodes, MnT node failover might
result in loss of logs or reports.
Note
These ports are required in all types of deployments irrespective of
being On-Prem or cloud.
LogAnalytics(Kibana) Port 5701 on MnT nodes should be opened for communication between
PAN and MnT nodes.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces,
or Bond 1 and Bond 2
SCEP TCP/9090 —
IPsec/ISAKMP UDP/500 —
TrustSec Use HTTP and Cisco ISE REST API to transfer TrustSec data to network
devices over port 9063.
TC-NAC TCP/443
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces,
or Bond 1 and Bond 2
Note
Default ports are configurable for external logging.
Note
UDP port 3799 is not configurable.
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces,
or Bond 1 and Bond 2
External Identity Sources and • Admin User Interface and Endpoint Authentications:
Resources (Outbound)
• LDAP: TCP/389, 3268
• SMB: TCP/445
• KDC: TCP/88
• KPASS: TCP/464
• WMI : TCP/135
• ODBC:
Note
The ODBC ports are configurable on the third-party database server.
Note
For external identity sources and services reachable only through an
interface other than Gigabit Ethernet 0, configure static routes accordingly.
Web Portal Services: HTTPS (Interface must be enabled for service in Cisco ISE):
- Guest/Web Authentication • Blocked List Portal: TCP/8000-8999 (default port is TCP/8444)
- Guest Sponsor Portal • Guest Portal and Client Provisioning: TCP/8000-8999 (default port is
- My Devices Portal TCP/8443)
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces,
or Bond 1 and Bond 2
Bring Your Own Device • Provisioning - URL Redirection: See Web Portal Services: Guest Portal
(BYOD) / Network Service and Client Provisioning.
Protocol (NSP)
• For Android devices with EST authentication: TCP/8084. Port 8084
- Redirection must be added to the Redirect ACL for Android devices.
- Provisioning • Provisioning - Active-X and Java Applet Install (includes the launch
- SCEP of Wizard Install): See Web Portal Services: Guest Portal and Client
Provisioning
• Provisioning - Wizard Install from Cisco ISE (Windows and Mac OS):
TCP/8443
• Provisioning - Wizard Install from Google Play (Android): TCP/443
• Provisioning - Supplicant Provisioning Process: TCP/8905
• SCEP Proxy to CA: TCP/443 (Based on SCEP RA URL configuration)
Mobile Device Management • URL Redirection: See Web Portal Services: Guest Portal and Client
(MDM) API Integration Provisioning
• API: Vendor specific
• Agent Install and Device Registration: Vendor specific
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond 0 Ports on Other Ethernet Interfaces,
or Bond 1 and Bond 2
• DHCP: UDP/67
Note
This port is configurable.
Note From Cisco ISE Release 3.1, all pxGrid connections must be based on pxGrid Version 2.0. pxGrid Version
1.0-based (XMPP-based) integrations will cease to work on Cisco ISE from Release 3.1 onwards.
pxGrid Version 2.0, which is based on WebSockets, was introduced in Cisco ISE Release 2.4. We recommend
that you plan and upgrade your other systems to pxGrid 2.0-compliant versions in order to prevent potential
disruptions, if any, to integrations.
The following table lists the ports used by the pxGrid Service nodes:
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond Ports on Other Ethernet Interfaces
0 (Gigabit Ethernet 1 through 5, or
Bond 1 and Bond 2)
Cisco ISE Service Ports on Gigabit Ethernet 0 or Bond Ports on Other Ethernet Interfaces
0 (Gigabit Ethernet 1 through 5, or
Bond 1 and Bond 2)
Feature URLs
Telemetry [Link]
Note In Cisco ISE Release 3.1 and earlier releases, Cisco ISE Smart Licensing uses [Link] as the
required internet URL until specific patch releases. See the installation guides for the relevant Cisco ISE
release for more information.
The Interactive Help feature needs Cisco ISE to connect to the following URLs using the administration portal
browser:
• *.[Link]
• *.[Link]