Cisco Ise
Cisco Ise
Cisco Ise
Introduction
Compliance: Enables effective corporate governance by creating consistent policy across an infrastructure.
Efficiency: Helps increase IT and network staff productivity by automating traditionally labor-intensive tasks and
streamlining service delivery.
Overview
Security: Secures your network by providing real-time
visibility into and control over all users and devices on
your network.
Solution Highlights
Business-relevant policies: Enables centralized, coordinated policy creation and consistent policy enforcement
across the entire corporate infrastructure, from head office to branch office.
Consolidated Services,
Software Packages
M
G
R
Session Directory
Flexible Service
Deployment
ACS
User ID
NAC Manager
NAC Profiler
ISE
NAC Server
NAC Guest
Location
Access Rights
Admin
Console
M&T
Distributed PDPs
Policy Extensibility
Manage Security
Group Access
Systemwide Monitoring
and Troubleshooting
SGT
Public
Private
Staff
Permit
Permit
Guest
Permit
Deny
2011 Cisco Systems, Inc. and/or its affiliates. Cisco and the Cisco Logo are trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and other countries. A listing of Ciscos trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks
mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1007R)
At-A-Glance
Systemwide operational visibility: Discovers, assesses, and monitors users and endpoints and employs advanced
troubleshooting capabilities to give IT teams complete visibility into who and what is on the corporate network.
Context-aware enforcement: Gathers information from users, devices, infrastructure, and network services to
enable organizations to enforce contextual-based business policies across the network. Cisco Identity Services
Engine acts as the single source of truth for contextually rich identity attributes, including connection status, user
and device identity, location, time, and endpoint health.
Flexible services architecture: Combines AAA, posture, profiling, and guest management capabilities into a single
appliance platform. Cisco Identity Services Engine can be deployed across the enterprise infrastructure, applying
the appropriate services supporting 802.1x wired, wireless, and VPN networks.
Benefits
Deployment Services
Personalized, professional services from Cisco and
our partners provide policy review, analysis, and
design expertise to prepare your network to deploy
a Cisco TrustSec solution that features Cisco Identity
Services Engine. Using leading practices, Cisco
TrustSec deployment services help you quickly and
cost-effectively deploy a full authentication and access
solution while providing knowledge transfer for ongoing
operational efficiency.
Guest
Users
Cisco Nexus
Cisco Catalyst 7000 Switch
Switch
Cisco Catalyst
Switch
802.1X
IP Phones
STOP
Campus
Network
STOP
STOP
Users,
Endpoints
Network-Attached
Device
WLC
Protected
Resources
Deployment Components
The Identity Services Engine is part of an infrastructure-based Cisco TrustSec deployment using Cisco network
devices to extend access enforcement throughout a network. Additional deployment components include Cisco
NAC Agent and Cisco AnyConnect (or a 802.1x supplicant) on the endpoint; Cisco Catalyst switches and Cisco
wireless LAN controllers acting as policy enforcement points for the LAN; and Cisco Adaptive Security Appliances for
secure remote access. Cisco Identity Services Engine also integrates with directory services such as Microsoft Active
Directory and Sun ONE Directory Server as policy information points.
2011 Cisco Systems, Inc. and/or its affiliates. Cisco and the Cisco Logo are trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and other countries. A listing of Ciscos trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks
mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1007R)
At-A-Glance
The Wireless license is intended for organizations that want to start their ISE deployment for policy decision for
wireless endpoints only. The features included as part of this license includes the Base and Advanced license
features.
The Wireless Upgrade license is for customers who deployed ISE for wireless endpoints only and want to expand
their deployment to wired and vpn endpoints.
Policy-Governed
Networks
Po
lic
Cisco TrustSec
Internet
? Device
Driving
towards
Policy Management
Policy-Enabled Services
Policy Based on
Business objects
ss
Guests
Bu
s
Initial
target
olicies
vant p
ele
s-r
es
in
Full
Quarantine
Business-relevant policies
Context awareness
Visibility and control
d Networks
rne
ve
Go
y
ntrol
nd co
ya
ilit
sib
Vi
Cisco Identity
Services Engine
Dramatically reduces cost of ownership with worldclass monitoring and troubleshooting features
designed to streamline operations for your helpdesk
and support teams.
C o n te x
t aw
ar
e
en
Cisco Vision
The first release of Cisco Identity Services Engine
focuses on the pervasive service enablement of Cisco
TrustSec for Cisco Borderless Networks. Future release
features will include the ability to propagate consistent
service policies throughout the network, from any
endpoint to the data center in areas such as virtualization
and branch office service prioritization.
2011 Cisco Systems, Inc. and/or its affiliates. Cisco and the Cisco Logo are trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and other countries. A listing of Ciscos trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks
mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1007R)
C45-654884-01 08/11