
Discover how Cisco identity services engine centralizes identity and context to enforce posture, profiling, device administration, guest access, and bring your own devices through centralized policy management.
Learn to install and configure Cisco ISE on VMware Workstation by importing the appliance, configuring a single management interface with IP, DNS, and admin credentials, then access the graphical UI.
Learn how to add, install and configure Cisco ISE on Eve-NG, including preparing a large disk, increasing storage to 200 GB, allocating RAM, and setting the IP address.
Master Cisco ISE 2.4 CLI basics by navigating exec and configuration modes, using help and question marks, and performing common commands for interfaces, time zone, and users.
Explore the Cisco Identity Services Engine dashboard on first login, review metrics and widgets for endpoints, system performance, alarms, and authentication, and learn about profiles, personas, and help resources.
Identify devices and users in Cisco ISE by defining identities, choosing local or external identity stores (Active Directory, certificate authority, RSA tokens), and applying personas for administration, monitoring, and policy.
Discover Cisco ISE's three personas—monitoring, policy administration, and policy service—and how they unify logs, reporting, diagnostics, and device administration in a single work center for endpoint identity management.
Explore Cisco ISE deployment options, from stand-alone deployments handling administration, policy services, and monitoring to distributed and fully distributed setups that provide redundancy and high availability.
Learn how Cisco ISE enables centralized device administration and network access control across routers, switches, firewalls, and wireless controllers, with role-based privileges and local privilege authorization fallback.
Explore the three core concepts of aaa: authentication, authorization, and accounting, and see how Cisco ISE provides centralized management for network devices using a local database.
Compare tacacs+ and radius protocols for aaa, noting tacacs+ is a Cisco proprietary tcp-based device administration protocol, while radius is an open standard udp-based protocol for network access.
Learn the 802.1X dot1x port-based authentication framework, including extensible authentication protocol, supplicant, authentication server, and authenticator components, and how they authenticate users to grant network access.
Explore 802.1X port states on Cisco switches, including authorized and unauthorized. Review host modes: single host, multi host, multi domain, and multi identification, and how they interact with Cisco ISE.
Configure and verify the 802.1x dot1x lab using a Cisco switch as authenticator, Windows 7 as supplicant, and Cisco ISE for radius-based authentication, authorization, and accounting.
Learn how to use mac address authentication bypass to authenticate devices lacking 802.1x; map mac addresses to credentials in the Cisco ISE database, and enforce restrictions as needed.
Explore the concept of downloadable ACLs (DACL) and how Cisco ISE can push policies to many switches automatically, enabling group- and user-based access control with dynamic, centralized updates.
Configure and verify downloadable ACLs in Cisco ISE 2.4, linking authorization policies to dynamically push ACLs to switches and restrict server access based on user authentication.
Explore dynamic VLAN concepts, where interfaces are assigned to VLANs automatically upon authentication, contrasting static VLANs and enabling guest or printer VLANs via MAB and Cisco ISE integration.
In Cisco ISE 2.4 basic training, configure and verify dynamic VLAN (DVLAN) policies, profiles, and downloadable ACLs, then test authorization and automatic interface assignment via radius logs.
Learn central web authentication (CWA) and web portal login, where devices are redirected to a Cisco ISE portal for guest or temporary access with customizable templates.
Configure and verify central web authentication in a lab using Cisco ISE 2.4, with supplicants, authenticators, and web portal redirects to policy-based authorization.
Learn to configure centralized device administration with tacacs, create admin and support groups, register devices, apply authorization policies, enable services, and audit commands with accounting.
Explore guest services in Cisco ISE, including hotspot portals, sponsored or registered guest portals and isolated networks. Understand daily, weekly, contractor, and social login guest types, with authentication and controls.
Explore the bring your own device concept in Cisco ISE, detailing how personal devices are registered, provisioned, and governed by policies to securely access corporate resources.
Explore change of authorization (CoA) and dynamic authorization in Cisco ISE 2.4, enabling policy updates when a new device connects to a switch and forces re-authentication.
Explore how Cisco ISE 2.4 uses profiling, profiler services, and probes to dynamically detect and classify endpoints—like Windows and Apple devices—by device type, OS, and network attributes.
Discover how Cisco ISE 2.4 uses multiple probes to profile endpoints, map devices by MAC address, and assign Windows 7 or Apple profiles through MAB authentication.
Evaluate endpoint posture in Cisco ISE to ensure health and security before network access. Verify antivirus, OS updates, firewall, registry keys, and other files across devices before joining.
Learn how Cisco ISE enforces endpoint compliance through posture assessment, health checks, and conditions that classify devices as compliant, non-compliant, or unknown.
Master EVE-NG installation, configuration, and image management for network labs, compare GNS3 and EVE-NG, and learn how to deploy routers, switches, and firewalls in a community edition.
Master Network Access Control, Zero‑Trust Enforcement, Profiling, Posture, TACACS+, and Full ISE Deployment
This course is designed to teach you everything you need to deploy, configure, and operate Cisco Identity Services Engine (ISE) quickly and confidently. You will learn the “how‑to” of ISE through structured lessons, real configuration workflows, and hands‑on demonstrations that build practical skills for real enterprise environments.
Cisco ISE is a core component of modern Zero‑Trust architectures. It provides centralized identity management, device visibility, secure access control, and automated policy enforcement across wired, wireless, and VPN networks. With ISE, organizations gain deep insight into who and what is connecting to the network — and can enforce security policies dynamically and consistently.
This course gives you the knowledge and hands‑on experience to deploy ISE, configure authentication and authorization policies, implement profiling and posture, secure administrative access, and integrate ISE with network infrastructure for full visibility and control.
What You Will Learn
ISE Deployment & Installation
ISE deployment scenarios (standalone, distributed, personas)
Installation, bootstrapping, and initial configuration
Licensing, certificates, and system setup
Integrating ISE with Active Directory
Authentication & Authorization
802.1X fundamentals and configuration
Authentication policies (wired, wireless, VPN)
Authorization rules and policy sets
Identity sources, groups, and user/device classification
Profiling & Posture
Device profiling concepts and probes
Posture assessment and compliance checks
Agent‑based and agentless posture flows
Remediation actions and enforcement
Guest Access & Web Authentication
Guest portals and sponsor workflows
WebAuth configuration
BYOD onboarding flows
Certificate provisioning for personal devices
TACACS+ Device Administration
TACACS+ configuration for network devices
Command sets, shell profiles, and admin roles
Securing administrative access across routers, switches, firewalls
Visibility, Monitoring & Troubleshooting
Live Logs, RADIUS logs, TACACS+ logs
Context visibility dashboards
Endpoint identity tracking
Troubleshooting authentication, authorization, and posture issues
Zero‑Trust & SD‑Access Integration
Role of ISE in Zero‑Trust architectures
Policy enforcement and segmentation
ISE integration with Cisco DNA Center
Automating network segmentation in IT and OT environments
Why This Course Is Valuable
Step‑by‑step “how‑to” guidance for real ISE deployments
Hands‑on practice with authentication, authorization, profiling, posture, TACACS+
Clear explanations suitable for beginners and experienced engineers
Covers all major features used in enterprise ISE environments
Ideal for Zero‑Trust, SD‑Access, and secure access control projects
Helps you build job‑ready skills for network security roles
Who Should Enroll
Network & Security Engineers
SOC/NOC Analysts
Identity & Access Control Engineers
Zero‑Trust and SD‑Access practitioners
IT professionals deploying secure access solutions
Students preparing for Cisco security certifications
Prerequisites
Basic networking knowledge (IP, VLANs, authentication concepts)
Familiarity with Cisco networking recommended
No prior ISE experience required
Start Mastering Cisco ISE Today
Gain the skills to deploy, secure, and operate Cisco Identity Services Engine — and build the foundation for modern Zero‑Trust network access.