
Introduction to the course and what you should expect.
How to configure VMware to support ISE, the Virtual WLC, and Windows.
Building the switch configuration to support the entire Lab.
The ASA configuration to support Internet access for our endpoints.
Configuration of the Windows Server to mock a real-world deployment - This includes Active Directory, DNS, DHCP, and the Microsoft CA Server to issue client-side certificates to machines and users.
Setting up the SSIDs and Security configuration for the ISE integration.
The initial ISE installation on both ISE Servers.
A brief walkthrough of the ISE CLI and GUI.
How the ISE Certificate stores work and why they are so critical to a successful ISE deployment.
A brief look at the different types of ISE personas.
A look at the common protocols used in most ISE deployments.
The various ways you can setup ISE for redundancy and scalability.
A brief overview of the various design considerations.
Building the full ISE deployment using both servers.
An overview of how ISE high availability works.
How to patch an ISE deployment.
The built-in backup and restore functions.
ISE deployment upgrade and various caveats.
The integration with ISE and Microsoft Active Directory.
Configuration of the built-in management system.
ISE Logging and Alerting.
A very brief overview of licensed features.
Lecture goes over monitor-mode, low-impact mode, and closed mode.
How to integrate your network access devices (switches, controllers, etc...) with ISE.
A walkthrough of the authentication system and how to configure and optimize.
Our first look at user authorization and DACLs.
The required switch configuration to support ISE.
How and why to use MAC Address Bypass.
Authentication and Authorization of a Active Directory user with PEAP.
The relatively new Easy Connect feature, overview and configuration.
The ins and outs of dual authentication with ISE.
Changing all configuration from PEAP to EAP-TLS using an automatic certificate deployment from Active Directory.
How the device profiling system works, including the configuration of a custom profile.
How to use client provisioning to automatically deploy Anyconnect and associated configuration files.
Configuration and testing of the ISE Posture component.
How to configure and use EAP-Chaining with EAP-FAST.
Configuration of the Cisco Virtual Wireless LAN Controller to support ISE functions.
Building a basic wireless policy to support authentication and authorization.
How to setup ISE for wireless guest access. Several different methods are covered.
Ensure guest devices have a minimum security posture before connecting to the network.
How to onboard personal devices for use on the corporate network.
Testing our deployment failover.
How to configure the newer version of switch code to support ISE.
A brief overview of TACACS+ with ISE, including configuration and testing.
A brief look at how to use ISE to authenticate/authorize remote access VPN users on an ASA.
All slides from the course in the PDF format.
This course is designed to teach you everything you need to know to get up and running with ISE quickly.
The course was built from the ground up in late 2018 and early 2019 and covers ISE Version 2.4.
Complete and unlimited access to:
All ISE basic configuration.
ISE for the Wired Network
ISE for the Wireless Network
Guest, BYOD, Posture, and much more!
All students will receive full access to all lessons, which includes the ability to download the videos directly. In addition, you will also be granted access to a members-only forum where I will help you when/if you get stuck on a topic.
If you would like to see more information on any given topic, just let me know. I’m happy to update a video or even create a new one to cover something more in-depth.