Overview
Provides a consolidated list of network ports required for secure communication between Cisco ISE nodes, network devices, endpoints, and external services, helping you plan firewall rules, support authentication and policy services, and avoid misconfiguration.
Ports used by all Cisco ISE personas
Lists the TCP and UDP ports required for inter-node communication and network device integration across all Cisco ISE persona
Cisco ISE infrastructure requirements
Provides a definite set of infrastructure requirements and limitations for deploying Cisco ISE.
Operating system ports
Lists the TCP ports required to enable NMAP-based operating system profiling and device discovery within Cisco ISE.
Administration node ports
Lists TCP ports required to access and manage the Cisco ISE Policy Administration node for administrative tasks and web-based configuration.
Monitoring node ports
Lists the TCP and UDP ports required to facilitate data collection, logging, and reporting services on the Cisco ISE Monitoring node.
Policy Service node ports
Lists the TCP and UDP ports required to support authentication, authorization, and accounting traffic on the Cisco ISE Policy Service Node (PSN).
Cisco pxGrid service ports
Lists the TCP ports required to enable secure communication and context sharing between Cisco ISE and third-party platforms using Cisco pxGrid.
OCSP and CRL service ports
Lists the TCP ports required to facilitate certificate validation and revocation status checks through OCSP and CRL services.
Cisco ISE processes
Describes the services and daemons that manage the core functionality, performance, and operational health of Cisco ISE and their service impact.
Required internet URLs
Lists essential external URLs that must be reachable by Cisco ISE to support critical functions such as license management, software updates, and cloud-based services.