Cisco Secure Access Help

PDF

Cisco Secure Access Help

Integrate ISE (Identity Services Engine) with Secure Access

Want to summarize with AI?

Log in

Integration Identity Services Engine with Secure Access to share network context and apply consistent security enforcement for users, devices, and workloads.


Cisco Identity Services Engine (ISE) integrates with Cisco Secure Access to share network context between the platforms for the purpose of applying consistent security enforcement for users, devices and workloads across the enterprise. This integration allows IT teams to:

  • Verify user identity: ISE verifies user identity, providing visibility into every device.

  • Enforce adaptive policies: ISE enforces adaptive policies to secure access to applications.

  • Employ zero-trust security: ISE enables zero-trust security functions for traffic that goes through the SD-WAN fabric.

  • Use anti-malware protection: ISE can use an anti-malware protection (AMP) agent to identify malicious files on endpoints.

  • Prevent USB device insertion: ISE can prevent the insertion of USB devices into endpoints.

This section describes how to enable context sharing between Cisco ISE and Cisco Secure Access.


Solution Overview

You can use Cisco Identity Services Engine (ISE) to define and use security group tags (SGTs) for classifying traffic in a Cisco TrustSec network. SGTs specify the privileges of a traffic source within a trusted network. Cisco ISE and Cisco TrustSec use a feature called Security Group Access (SGA) to apply SGT attributes to packets as they enter the network. These SGTs correspond to a user's assigned security group within ISE or TrustSec. If you configure ISE as an identity source, Secure Access can use these SGTs to filter traffic.

With this integration, Cisco Secure Access administrators can use the rich enterprise context shared from Cisco ISE to configure simpler but granular policy control towards internet/SaaS for branch users. Cisco ISE, in conjunction with Catalyst SD-WAN, shares the network context (ISE SGTs and SD-WAN VPN IDs) with Cisco Secure Access.

Use cases for context-aware security enforcement can revolve around employees, guests, or IoT networks behind a Catalyst SD-WAN branch that need to securely access internet/SaaS applications, with Cisco Secure Access providing cloud-based security enforcement.



Note

For information about context sharing with Cisco Catalyst SD-WAN, see Integrate Catalyst SD-WAN with Secure Access.


Security Group Tags

A Securitygroup tag (SGT) is a label used to facilitate classification, propagation and enforcement by associating the SGT with an IP, VLAN, or port-profile as a source or destination. Matching on SGT tags provides the following benefits:

  • The management center can subscribe to Security Group Tag eXchange Protocol (SXP) mappings from ISE.

  • ISE uses SXP to propagate the IP-to-SGT mapping database to managed devices. When you configure management center to use an ISE server, you enable the option to listen to the SXP topic from ISE. This causes the management center to learn about the security group tags and mappings directly from ISE. The management center then publishes SGTs and mappings to managed devices.

    For the SGT tag to be in the packet, the switches and routers in the network must be configured to add them. See the ISE documentation for information on how to implement this method.

  • The SGT assigned to the user session, as downloaded from the ISE session directory. The SGT can be matched to source or destination.

  • You can create security group tags in ISE and assign host or network IP addresses to each tag. You can also assign SGTs to user accounts, and the SGT is assigned to the user's traffic. If the switches and routers in the network are configured to do so, these tags then get assigned to packets as they enter the network controlled by ISE, the Cisco TrustSec cloud.

  • Supports Cisco TrustSec, which enables you to segment your network to protect critical business assets.

SGT Matching

If you use ISE to define and use security group tags (SGT) for classifying traffic in a Cisco TrustSec network, you can write access control rules that use SGT as a source matching criteria. This enables you to block or allow access based on security group membership rather than IP addresses or network objects.

SGT Limitations

Before you start using SGTs in your Access policy, consider the following limitations:

  • Security Group Tags can only be used as source and not destination matching criteria in access control rules.

  • RA-VPNs do not receive SGT mappings directly through RADIUS.


Components and Prerequisites

This topic describes the components and prerequisites required for integrating Catalyst SD-WAN with Secure Access.

Components Used

The information in this integration section is based on the following components:

  • Cisco Secure Access—A cloud-based security service edge (SSE) solution that provides zero-trust network access to allow users to easily connect to the internet and private applications from any device

  • Cisco Identity Service Engine (ISE) Version 3.3 Patch 1 (or newer)

  • Cisco pxGrid Cloud—A cloud-based solution that enables administrators to share contextual information between on-prem applications (such as Cisco ISE) and cloud-based solutions (such as Secure Access) without compromising the security of your network. See the Cisco pxGrid Cloud Solution Guide for complete information.

  • Cisco DNA Portal—Activate Cisco Network Experience Applications for your Cisco products. Onboard new capabilities and get more out of your network.

  • Cisco Security Cloud Control—A unified management solution for your Security Cloud products and identity. Security Cloud Control is included with Secure Access.

Prerequisites

The information in this integration section assumes the following prerequisites:

  • A Cisco account.

  • A working knowledge of Cisco Secure Access (with full Administrator access).

  • A working knowledge of Cisco Identity Services Engine (ISE) (v3.3 patch 1 or newer with full Administrator access).

  • Access to and credentials for:

    • Cisco pxGrid Cloud.

    • Cisco DNA Portal.

    • Cisco Security Cloud.

  • (Optional) A working knowledge of Cisco Catalyst SD-WAN configuration and features; see Integrate Catalyst SD-WAN with Secure Access.


Solution Workflow

This topic describes the workflow to set up context sharing between Cisco Identity Services Engine (ISE) and Cisco Secure Access works for Security Group Tags (SGTs).

This section breaks up the overall configuration into the following main steps:

  1. Connect Cisco ISE and Cisco pxGrid Cloud.

  2. Enable the Cisco Security Cloud Exchange.

  3. Integrate Cisco ISE with Cisco Secure Access.

  4. Verify Security Group Tags in Cisco Secure Access.


Connect Cisco ISE and Cisco pxGrid Cloud

This section describes how to set up and complete the integration between Cisco Identity Services Engine (Cisco ISE) and Cisco pxGrid Cloud.

About Cisco pxGrid Cloud

Cisco pxGrid Cloud is a cloud-based solution that enables you to share contextual information between on-premises applications such as Cisco ISE and cloud-based solutions such as Cisco Secure Access without compromising the security of your network. It is secure and customizable, enabling you to share only the data that you want and consume only the contextual data that is relevant to your application.

Cisco pxGrid Cloud offers the following benefits:

  • Plug-and-play deployment without requiring infrastructure changes to your network.

  • Cisco ISE as a single source of truth for endpoint identity by delivering consistent context exchange with on-premise and cloud partners.

  • Enrichment of Software as a Service-based (SaaS-based) security analysis with real-time endpoint context from Cisco ISE.

  • Threat containment by isolating endpoints from the network through actions initiated from the security SaaS solutions.


Cisco pxGrid Cloud Terminology

The following are some of the common terms that are used in the Cisco pxGrid Cloud solution and their meaning in the Cisco pxGrid Cloud environment:

  • Offer—A set of capabilities packaged together and offered as a solution.

  • Subscription—An instance of an offer being consumed by a tenant is a subscription.

  • App—You can create and register applications for your product based on your requirements. For example, you can create an app that can retrieve the session and endpoint data from Cisco ISE.

    Applications with a cloud offering can be onboarded to Cisco pxGrid Cloud. After an application is onboarded, you can share data between your Cisco ISE deployment and the application.


Cisco pxGrid Cloud and Cisco ISE Integration Workflows


Enable Cisco Security Cloud Exchange

Procedure

  1. Claim your security cloud subscription. The claim link would be sent to the cloud account administrator via email. See the sample message below:


    The Claim Subscription interface.
  2. Log in and verify that your cloud account subscription is associated with your provisioned Secure Access organization. To do so, navigate to the Overview screen. You should see Cisco Secure Access listed under Products as shown in the following example view.


    The Scc Overview interface.
  3. Next, navigate to Users to see a list of the user(s) that are members of your Cisco Security Cloud enterprise as shown in the following example view. You'll want to choose one user to be the administrator for integration services.


    The Scc Users interface.
  4. Click the ellipse icon (. . .) for the user you've chosen as the integrations administrator, then click Edit.


    The Scc Admin interface.
  5. Click Assign roles to user and click + Add Row.

  6. Under Product or Service, choose Integrations Service and under Role(s) check Administrator, then click Assign roles.


    The Scc Assign Roles interface.
  7. Open a new browser tab to sign in to Cisco Secure Access using the Integrations Service admin account you just created. Your Secure Access login link will be in this format: (https://dashboard.sse.cisco.com<SecureAccessOrgID/overview>)

  8. Navigate to Admin > Management > Integrations. You should see the resulting Integrations page similar to the following example.


    The Secure Access Integration interface.
    Note

    If your integrations page does not load or displays an error, reach out to your Cisco representative or Cisco Support for assistance.


Integrate Cisco ISE with Secure Access

This topic describes how to complete the integration between Cisco ISE and Cisco Secure Access.

Procedure

  1. Return to the Cisco DNA Portal tab, search for the Cisco Security Cloud application, and click Activate.


    The Scc Activate interface.
  2. Choose Authenticate your application and copy the resulting token to your clipboard by clicking the copy icon.


    The Secure Access Authenticate interface.
  3. Click Exit.

  4. Return to the Secure Access tab.

  5. Navigate to Admin > Management > Integrations.


    The Secure Access Integrate Ise interface.
  6. Click Integrate to add the ISE integration.

  7. Enter a Name for the ISE integration, paste in the copied token, and then click Save.


    The Secure Access Integrate Ise Name interface.
  8. The system returns a confirmation banner indicating a New ISE Cluster added.

  9. Expand the integration pane to view the status of the ISE cluster (waiting for activation).


    The Secure Access Integrate Ise Waiting interface.
  10. Return to the Cisco DNA Portal tab and the Cisco Security Cloud application.

  11. On the Cisco Security Cloud tile, click Manage.


    The Scc Manage interface.
  12. Choose Add and select the ISE application instance.


    The Scc Add Ise Instance interface.
  13. Choose the application instance that will be associated with your subscription, then click Next.


    The Scc Choose Ise Instance interface.
  14. Choose the product for which you want to associate the application. In this example choose Cisco ISE, then click Next.


    The Scc Associate interface.
  15. Choose capabilities and API access for the application and click Next.


    The Scc Capabilities interface.
  16. Review the application summary. You can click Edit to make any changes. Click Activate to complete the setup.


    The Ise Scc Summary interface.

    The Scc Activate Final interface.
  17. Monitor the Cisco Security Cloud dashboard to view the status.


    The Scc Monitor interface.
  18. Once the instance is active in Cisco Security Cloud, it should sync to Cisco Secure Access. You can switch between the tabs to view the state of the sync.

What to do next

We strongly recommend modifying or creating a private access rule to further incorprate this successful integration. You can now include private IP addresss from the security group tag (SGT) originating from the ISE appliction as either the source or the destination.


Verify and Monitor Context Sharing

This section describes how to verify context sharing between Cisco ISE and Secure Access works for Security Group Tags (SGTs).


Verify Context Sharing in Secure Access

Security Group Tags (SGTs) are added to Secure Access as source resources when Cisco ISE is integrated with Secure Access. Once added, these SGTs can be used when configuring access rules. See Security Group Tags for more information.

Procedure

  1. Navigate to Resources > Sources and Destinations > Security Group Tags to verify that the SGTs are shared as resources.


    The Sgt Resources interface.
  2. Navigate to Secure > Policy > Access Policy.

  3. Click the Add Rule drop down and choose Internet Access to verify that the SGTs are shared as source objects for internet access rules.


    The Sgt Access Rule interface.
  4. From the Select sources drop down, choose Security Group Tags as a rule source.

    From there, you can select Any Security Group Tag, which will include all existing and future SGTs in the rule. Alternately, you can select any (or all) existing SGTs for more granular internet access rules.


Activity Search in Secure Access

To search for activity from the sources in your environment over a selected time period, use the Activity Search report. The report lists all security (and non-security) activity for the sources reporting to Secure Access for the selected time period.

Procedure

  1. Navigate to Monitor > Reports > Activity Search. This takes you to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.


    You to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.
  2. Hover over individual column values to apply it as a search filter or to exclude it from the search.