To enable connectivity between a Cisco ISE deployment and Cisco pxGrid Cloud, the pxGrid Cloud option must be activated on one or two pxGrid nodes in the Cisco ISE deployment. If you have configured high availability for pxGrid nodes, one of the nodes acts as the Active node and the other acts as the Standby node. The Standby node assumes the role if the Active node fails.
Only the Active node establishes connection to Cisco pxGrid Cloud and handles the traffic between the Cisco ISE deployment and Cisco pxGrid Cloud. No other Cisco ISE node interacts with Cisco pxGrid Cloud.
The pxGrid Cloud agent acts as a bridge between Cisco ISE and Cisco pxGrid Cloud. A pxGrid Cloud application can subscribe to a pxGrid topic. The pxGrid Cloud agent in Cisco ISE learns about this subscription from Cisco pxGrid Cloud and establishes the actual subscription to the pxGrid service in Cisco ISE. When the agent receives a notification on the pxGrid topic, it forwards the notification to Cisco pxGrid Cloud over a logical channel dedicated to the pxGrid service. The pxGrid Cloud application can invoke ERS, pxGrid, and OpenAPIs within the Cisco ISE deployment. The pxGrid Cloud agent proxies a REST request from Cisco pxGrid Cloud to Cisco ISE, and returns the response to Cisco pxGrid Cloud.
Cisco ISE customers with a pxGrid Cloud subscription can register their deployment with Cisco pxGrid Cloud and use the applications in the offer. To do this, you must:
-
Acquire and activate the pxGrid Cloud subscription.
-
Enable the pxGrid Cloud service on one or two pxGrid nodes in the Cisco ISE deployment.
-
Register the Cisco ISE deployment with Cisco pxGrid Cloud (associating it with the subscription) and receive an authentication token.
-
Enter the authentication token in the Setup Connection page in Cisco ISE ().
This activates the pxGrid Cloud agent on the Active pxGrid node and establishes a connection between the Cisco ISE deployment and Cisco pxGrid Cloud.
-
Select a Cisco pxGrid Cloud application from the offer and associate it with the subscription. The application then has access to the Cisco ISE deployment.