
Install Microsoft server 2008 on a VM, deploy Active Directory and certificate authority, and implement Cisco Identity Service Engine with its web portal; snapshot, backup, and upgrade with verification.
Learn how to install Microsoft Server 2008 on VMware Workstation by creating a custom VM, attaching installation media, and completing the initial setup with a password and network configuration.
Install and configure Active Directory on Windows Server 2008, promote a domain controller, create a new forest with a domain name, set administrator passwords, reboot, and verify services.
Install a certificate authority on Windows Server 2008 by adding the Active Directory certificate services role, configuring certification authority and web enrollment, and enabling network device enrollment services.
Install Cisco identity service engine on VMware, create a Linux Red Hat 6 64-bit VM, allocate resources, and configure hostname, IP address, DNS, and gateway during setup.
Learn how to take and manage virtual machine snapshots, including naming, saving state, and reverting to an installed Active Directory configuration and services.
Explore the Cisco ISE web portal and its administration, licensing, certificates, and identity management features. Learn to manage users, groups, devices, and authentication policies.
learn how to integrate Active Directory with ISE and build an identity source sequence that prioritizes a local database and then Active Directory, guiding authentication when a user isn't found.
Learn to configure ldap integration in Cisco ISE with active directory as an external identity source, test and bind, select groups, and build an identity source sequence.
Register the ISE with a self-signed certificate across primary and secondary nodes, export and import certificates, then configure a multicast group and verify replication and service startup.
Learn how to register ISE with Microsoft certificate authority, generate and submit certificate signing requests, import and bind certificates, and promote the deployment to primary with replication and restart.
Learn to back up ISE configurations by creating users, groups, and policies, configuring an ftp/ftb server repository, and performing a timestamped backup secured with an encryption key.
Learn to install Cisco ISE patches by downloading the patch bundle from Cisco, configuring an FTB server repository, transferring the patch, and verifying the ISE version after installation.
Roll back the ISE 1.1.4 patch on Windows 10, uninstall and reinstall the patch, and verify the identity service engine version afterward.
Upgrade Cisco ISE from 1.1.x to 1.2.0 using the FTB server and upgrade bundle, configure a repository, and verify services resume after the upgrade.
Configure SISAS ISE-1.1.4 lab initial setup by creating five networks (10/20/30/40/50) as virtual interfaces, enabling IP routing, and configuring DNS and DHCP; register APs with the WLC using option 43.
Configure mac authentication bypass (MAB) with ISE and enable radius-based authentication on the switch. Add the device MAC to ISE identities to authorize access.
Verify mac authentication bypass by configuring the workstation’s mac in the database, enable dhcp snooping, assign ip via the dhcp server, and confirm client access through the switch.
Learn to configure dot1x with MD5 on switches using a radius server and ISE, including interface authentication, radius settings, and user verification for secure network access.
Demonstrate dot1x with md5 verification on a switch, configuring a test PC through registry and wired settings to authenticate and obtain an IP on a trusted network.
Learn how to configure dynamic vlan with md5 using ise, including creating radius users and groups, defining authorization policies and profiles, and applying 802.1x with switch ports to assign vlans.
Configure dynamic VLAN with MD5 verification in ISE, validate user authentication, apply policy conditions and identity groups, and verify session connectivity and VLAN assignment for Shivah.
Learn to configure dynamic VLANs and DACLs with MD5 in ISE, including radius server setup, identity groups, and policy-based access rules for user traffic.
Demonstrate dynamic VLAN and downloadable DACL with MD5 verification in ISE 1.1.4, showing authentication sessions, ACL downloads, and internet access control based on user state.
Learn to configure 802.1x with PEAP using ISE, set up RADIUS authentication, create user Shivah with a pre-shared key, and verify authentication through a demonstration network.
Configure dot1x with peap verification on a switch, enable user authentication, set credentials, and verify the authentication session and ip address to ensure access.
Learn to configure dot1x with peap using Active Directory authentication, assign radius and identity sources, test authentication, and set policy rules for secure network access.
Demonstrate configuring dot1x with peap and Active Directory verification on wired clients, validating certificates, and monitoring authentication sessions to ensure Active Directory-based user access.
Configure dynamic VLAN with PEAP using ISE 1.1.4 by setting up a RADIUS server, user identities and groups, and applying a radius-based policy to enforce authentication.
explore dynamic vlan with peap verification in the ccnp security sisas 300-208 deep dive, illustrating test pc setup on port 48, authentication sessions, ip address assignment, and dhcp server interactions.
Explore dynamic VLAN and DACL configuration with PEAP authentication using RADIUS, identity management, and policy-based access on Cisco SISAS 300-208 deep dive.
Explore dynamic VLAN and dynamic DACL configuration with PEAP verification using ISE in SISAS 300-208, covering RADIUS authentication, access policy validation, and network resource access.
Learn to configure local web authentication (LWA) with a RADIUS server in SISAS 300-208, including ACLs, UDP ports 67 and 53, fallback profiles, and interface and policy setup.
Demonstrates configuring wired local web authentication (LWA) with ISE-1.1.4, verifying authentication on a test PC, and enforcing ACLs to allow DNS and DHCP before internet access.
Configure wired central web authentication (CWA) using map-based aaa, radius servers, and dynamic policy on a switch. Implement ip device tracking, ACLs, and a guest portal to manage authentication.
Demonstrate wired central web authentication (CWA) verification by configuring the SBC, observing authentication sessions, redirecting to internet after policy updates to permit dhcp, and validating IP and DNS assignment post-auth.
Configure mac authentication bypass and profiling on ISE, set up radius server authentication, map interfaces, and enable profiling probes to verify client authentication and session success.
Verify MAC authentication bypass and profiling verification on ISE, showing host authentication sessions, interface status, and IP address assignments, with endpoints registered by MAC address and a Windows 7 machine.
Configure central web authentication and profiling in ISE by setting up radius, DNS, DHCP, identity management, CWA groups, and profiling policies, then validate with interface and guest portal settings.
Explore central web authentication (CWA) and profiling verification in ISE, showing how devices gain access through pre-auth policies, MAC address learning, and dynamic database entries on the switch.
Install ise 1.4.0 on vmware using iso by creating a Red Hat Enterprise Linux 6 64-bit vm with a 200 gb disk, then configure network, ip, and dns.
Install ISE 1.4.0 on VMware using OVF by downloading from Cisco, importing the virtual appliance, and configuring network settings, domain name, DNS, and AD integration.
Access the web portal of ice 1.4.0, log in as admin, and navigate the system. Explore administration, licensing, certificates, network resources, identities, users, groups, and backup.
Learn how to integrate Active Directory with ISE 1.4.0 and configure identity source sequence, including joining AD, syncing users and groups, and applying policy settings.
Learn how to configure ldap integration in ISE 1.4.0 and set up an identity source sequence with Active Directory, including groups from directory, identity creation, and policy authentication settings.
Learn how to register ISE with a self-signed certificate, export and import system certificates, configure primary and secondary deployments, and verify service status and policy deployment.
Register ISE with Microsoft certificate authority by generating certificate signing requests, importing trusted certificates, and configuring deployment to promote primary and synchronize services.
Configure and back up Cisco ISE using a dedicated backup repository, FTB server, and an encryption key. Verify the backup status on the FTB server and confirm completion.
Learn to restore ISE 1.4.0 from a backup by configuring the Shivah repository with the encryption key on the FTB server, then reboot and verify services.
Learn how to install the Cisco identity service engine 1.4.0 patch (patch 7) on the identity services engine, configure the repository, unbundle the patch, reboot, and verify with application status.
Learn to roll back an ISE patch (ISE-1.4.0) by uninstalling the patch, rebooting the system, and verifying the absence of patch information.
Upgrade ISE from 1.4.0 to 2.0 using the FTB bundle and verify integrity. Reboot the system and ensure DNS and anti-peace hardware are reachable.
Demonstrates configuring mac authentication bypass on ISE 1.4.0, setting up a radius server, enabling switch port authentication, and adding endpoints with MAC addresses for ISE authentication, including testing results.
Demonstrates MAC authentication bypass verification in ISE, showing automatic endpoint creation on first connection, subsequent successful authentications, and lab steps using port 48 and live authentication sessions.
Configure 802.1x with MD5 on switches, set up a radius server, and enable host authentication. Define the user Shivah and credentials, then validate radius authentication.
Configure 802.1x with md5 verification in ISE, enable wired authentication, adjust registry entries and services, and verify successful authentication and network connectivity.
Configure dynamic VLAN assignment with MD5 authentication using ISE 1.4.0 and a RADIUS server, set up switch interfaces and policies, create users and groups, and verify policy results.
Configure and verify dynamic VLAN assignment with ISE 1.4.0 MD5 verification, through wired access, role-based authorization profiles, user groups, and authentication sessions.
Configure dynamic vlan and downloadable acl with md5 on ISE 1.4.0. Implement radius authentication, policy, and group-based access.
Verify dynamic vlan and downloadable ACL configuration with md5 verification in SISAS, demonstrating authentication, vpn connectivity, and ip configuration.
Learn to configure dot1x with peap on ISE 1.4.0, including setting up radius, authenticating switch ports, and testing user access via a test identity.
Verify dot1x with peap using ISE 1.4.0 and test client authentication on a Windows PC, configuring Microsoft Protected Extensible Authentication Protocol (PEAP) settings and confirming authentication sessions.
Configure dot1x with peap on ise 1.4.0 to enable radius-based authentication using Active Directory integration.
Master dot1x with PEAP and Active Directory verification in ISE-1.4.0, configure PKP settings on the client, and verify successful authentication and IP connectivity across the session interface.
Explore dynamic VLAN configuration with PEAP on ISE 1.4.0, covering RADIUS server setup, AAA authentication, 802.1X policy, and identity group management for secure access.
Demonstrate dynamic vlan assignment with peap verification through an eap-based authentication workflow. Validate authentication sessions on a test pc and confirm access to internal resources.
Configure dynamic VLANs and a downloadable ACL to enforce network access policies using 802.1x authentication and a RADIUS server in ISE 1.4.0.
Learn to configure dynamic VLANs and downloadable ACLs with PEAP verification on ISE 1.4.0, enabling authenticated access and precise policy enforcement for campus networks.
Configure wired local web authentication using ISE 1.4.0, set up radius and ACLs, implement a fallback profile, and validate user authentication on the switch.
Verify wired local web authentication with ISE 1.4.0 on the switch, test PC access, and configure radius; ensure users are in the correct group for success.
Configure wired central web authentication (CWA) with ISE 1.4.0, set up DNS and RADIUS, define policies and ACLs, and map wired hosts to the central web authentication profile.
Verify wired central web authentication using ISE-1.4.0 by connecting a test PC, obtaining an IP address, and confirming authentication and internet access on a Windows 7 workstation.
Configure MAC authentication bypass with profiling on ISE 1.4.0, upload the initial configuration, verify reachability, enable the RADIUS server and accounting, and enable profiling and DHCP probes for endpoint authentication.
Verify MAC authentication bypass (MAB) and profiling verification in ISE 1.4.0, confirm authentication sessions and device connectivity, and validate IP assignment and internet access.
Configure central web authentication (CWA) and profiling on Cisco ISE 1.4, including setting up RADIUS servers, AAA mapping, IP access lists, and profiling policies to secure network access.
Demonstrates central web authentication (CWA) and profiling verification for ISE 1.4.0, guiding through the interface, IP addressing, access lists, and validation of user identities and internet access.
Install ise 2.0.0 using an ovf image, download and import it, configure ip address, gateway, dns, domain name, and name server, then verify services with show application status.
Explore the ISE 2.0 web portal intro, navigating home, operations, policy, and administration; learn deployment, licensing, certificates, maintenance, and identity management for network access control.
Learn to integrate Active Directory with ICE 2.0, configure external identity sources and identity source sequence, join domains, manage groups, and set policy and default route.
Configure LDAP integration with ISE 2.0, add an external identity source, map the organization naming context and Active Directory groups, and set the identity source sequence for user routing.
Register ISE-2.0.0 with a self-signed certificate, configure primary and secondary deployments, import trusted certificates, create the Shivah group, and promote the secondary to primary while syncing.
Register ISE 2.0.0 with Microsoft certificate authority, generate and submit certificate signing requests, import and trust the issued certificates, and verify the primary and secondary deployment status.
Learn to back up Cisco ISE 2.0 to a backup repository via a shared folder, configure permissions, and verify the backup across two ISE nodes.
Explore the SISAS ISE-2.0.0 restore workflow: revert to a snapshot, restore from a backup repository, import the encryption key, and verify the running config and application status.
Configure a Shivah repository on the AP server, select the ISE patch bundle 2.0.0, run the batch install, and reboot to complete the ISE 2.0.0 patch.
Learn how to rollback a patch on Cisco ISE, including removing the patch from a node or all nodes, reinstalling, rebooting, and verifying ISE page information.
Upgrade ISE from 2.0.0 to 2.0.1 using the upgrade bundle and repository, ensuring AP servers are reachable. The process may reboot twice and take up to 30 minutes.
Learn how to configure mac authentication bypass (MAB) on ise-2.0.0, set up the radius server, create endpoint entries, and troubleshoot authentication with a test pc.
Demonstrate mac authentication bypass (MAB) verification on ISE 2.0, showing automatic mac address entries, successive authentication and authorization failures followed by successes, and profiling deployments with enabled probes.
Learn to configure dot1x with MD5 on ISE 2.0.0, set up a radius server, and perform identity authentication for secure network access.
Verify dot1x with md5 on ISE 2.0.0 by configuring radius, adjusting network card properties, and validating authentication on a test pc with a switch, showing successful authentications.
learn to configure dynamic vlan with md5 authentication using ISE 2.0.0, radius server setup, identity groups, and policy profiling to control access on the switch.
Explore the ISE 2.0.0 dynamic VLAN process with MD5 verification, configuring authentication and VLAN policies on a switch to ensure secure network access and session validation.
Demonstrate verifying authentication with MD5 checks, applying a dynamic VLAN and DACL in ISE 2.0, and validating internet access through IP access list policies.
Learn how to configure dot1x with peap on ise 2.0, set up a radius server and switch port control, and validate authentication for reliable access.
Learn to verify dot1x with peap on wired interfaces using ISE 2.0. Configure settings, perform authentication validation, and confirm device connectivity.
Configure 802.1x with PEAP using Active Directory authentication on a switch, integrate a radius server, join the AD domain, map directory groups, and verify authentication.
Verify dot1x with PEAP and Active Directory using ISE 2.0.0, configuring switch settings and testing authentication to access the internal network.
Learn to configure dynamic VLANs with PEAP on ISE 2.0, set up radius authentication, and build identities, groups, and policies for wired and wireless access.
Explore dynamic vlan with peap verification using ise 2.0.0, verify user authentication, enable certificate-based auth, and validate client connectivity to internal resources.
Learn to configure dynamic vlan and dacl with peap authentication in ISE 2.0.0, including radius settings, identity groups, policies, and downloadable acls for secure access.
Explore ISE 2.0.0 dynamic VLAN and DACL with PEAP verification, verify switch authentication, grant access via dynamic VLAN, apply DACL, and review RADIUS logs for network admission.
Learn to configure wired local web authentication with ISE 2.0, setting up radius servers, ACLs, proxy and fallback profiles, admission names, and LWA policy for secure wired access.
Verify wired local web authentication (LWA) with ISE 2.0, test client access, review ACL behavior and radius live logs to confirm external access while internal network is restricted.
Configure wired central web authentication with ISE 2.0.0, including dot1x radius, IP device tracking, dynamic ACLs, and CWA group policy mapping for wired clients.
Demonstrate ise-2.0.0 wired central web authentication (cwa) verification by connecting a test pc to a switch, completing authentication, and obtaining redirected internet access.
Configure mac authentication bypass and device profiling on the network switch using 802.1x, radius, and profiling probes to ensure secure access and visibility.
Master MAC authentication bypass (MAB) and profiling verification in SISAS 300-208. Connect a test PC to a switch, troubleshoot failures, configure IP, and verify DHCP and authentication across the network.
Configure central web authentication and profiling with radius-based aaa, policy rules, and identity groups. Enable probes, snmp, and device tracing to enforce access control and profiling across the network.
Master ISE 2.0 central web authentication (CWA) and profiling verification through hands-on steps to connect a PC to wifi, configure interfaces, and verify internet access.
Conclude the ccnp security sisas 300-208 deep dive with a final overview of critical topics and exam-focused review for secure access and threat defense.
The Implementing Cisco Secure Access Solutions (SISAS) (300-208) exam tests whether a network security engineer knows the components and architecture of secure access, by utilizing 802.1X and Cisco TrustSec. This 90-minute exam consists of 65–75 questions and assesses knowledge of Cisco Identity Services Engine (ISE) architecture, solution, and components as an overall network threat mitigation and endpoint control solutions. It also includes the fundamental concepts of bring your own device (BYOD) using posture and profiling services of ISE. Candidates can prepare for this exam by taking the Implementing Cisco Secure Access Solutions (SISAS) course.
CCNP Security 300-208 (SISAS) Module Contents in brief:
In this course we have covered Cisco ISE 3 versions (1.1.4, 1.4.0. 2.0.0)