CLS
Cybersecurity

Implementing and Configuring Cisco Identity Services Engine (SISE)

Total Duration
40 Hours
Level
Intermediate
Category
Cybersecurity
Partner
Cisco
About this course

About this course

The SISE course teaches IT professionals how to implement and configure Cisco Identity Services Engine (ISE) for secure network access, policy management, and threat mitigation. 

The Implementing and Configuring Cisco Identity Services Engine (SISE) training teaches you to deploy, configure, and operate Cisco® Identity Services Engine (ISE) as the central platform for identity-based access control. Learning begins with the core architecture and installation and progresses through network access control, identity stores, policy design, and day-to-day operations. You will learn how to configure authentication and authorization policies, create scalable guest onboarding workflows, integrate network devices, and apply identity-based access decisions across wired and wireless environments. It also covers endpoint profiling, posture assessment, Terminal Access Controller Access Control Server (TACACS+) device administration, certificate management, lifecycle operations, and advanced administration practices

Target Audience

Network engineers working with Cisco security and access control solutions
Network administrators managing wired and wireless enterprise access
Cybersecurity professionals who need to develop knowledge and skills in NAC technologies
IT professionals about to work with Cisco Identity Services Engine (ISE)

Prerequisites

Familiarity with Cisco Secure Client
Familiarity with Microsoft Windows operating systems
Familiarity with the Cisco IOS® Software Command-Line Interface (CLI) for wired

Course Outline

  • Cisco ISE Evolution, Foundation, and Role
  • Architecture and Design
  • Cisco ISE Installation and Initial Config
  • 802.1X in Cisco ISE
  • MAB in Cisco ISE
  • Network Device Integration with Cisco ISE
  • Identity Sources and Authentication Types
  • Active Directory and LDAP Integration
  • Identity Selection and Resolution Logic
  • Cisco ISE Policy Framework
  • Authentication Policies
  • Authorization Policies
  • Troubleshoot Policies and Sessions
  • Guest Access Overview
  • Guest Access Policies and Settings
  • Guest Portals and Lifecycle Operations
  • Sponsor Portals
  • BYOD Architecture and Use Cases
  • BYOD Onboarding with Native Supplicant Provisioning
  • BYOD Lifecycle Operations
  • Profiling Architecture and Capabilities
  • Probes and Data Collection
  • Profile Policies and Authorization
  • Profile Monitoring and Design
  • Posture Service Flow and Agents
  • Posture Updates and Client Provisioning
  • Posture Policies and Compliance-Based Access
  • Posture Testing and Monitoring
  • AAA and TACACS+
  • TACACS+ Device Administration
  • TACACS+ Command Authorization
  • Cisco Trust Sec Overview
  • Cisco Trust Sec in Cisco ISE
  • Cisco ISE Administration
  • Explore the Initial Cisco ISE Configuration, GUI and System Certificate
  • Configure Network Device Groups and Network Devices
  • Integrate Cisco ISE with Active Directory
  • Configure MAB
  • Configure Wired 802.1X
  • Configure Wireless 802.1X and Optional Wired EAP-TLS and TEAP
  • Troubleshoot Cisco ISE 8021.X Configuration Errors
  • Configure Hotspot Guest Access
  • Configure Sponsored Guest Access
  • Configure BYOD
  • Manage BYOD Devices
  • Configure Profiling
  • Configure Authorization Policy Rules and Run Profiler Reports
  • Configure Posture Preparations and Client Provisioning
  • Configure Posturing and Reporting
  • Configure TACACS+ Basic Device Administration
  • Configure TACACS+ Command Authorization
  • Configure Cisco TrustSec
Learning outcomes

What you'll learn

Explain how Cisco ISE plays a role in today's network security architecture along with its capabilities, rationale behind its design, and typical use cases
Evaluate the concept of 802.1X-based network access and Cisco ISE’s contribution to securing wired and wireless connection through identity-based access
Define the role of NADs in Cisco ISE’s authentication process, and outline the steps involved in adding, configuring, and verifying NADs in Cisco ISE
Evaluate the role of internal and external identity stores in Cisco ISE, along with identity management of users and devices and certificate-based authentication
Evaluate how to configure Cisco ISE to enable integration with Active Directory and LDAP to support external user authentication
Evaluate how Cisco ISE policies evaluate authentication policies based on rule conditions, identity store sequence, and dictionaries; discuss what happens when there are no matching rules
Analyse Cisco ISE policies based on logs, RADIUS flow data, and session context to troubleshoot authentication and authorization failures in various access scenarios
Analyze how Cisco ISE provides web-based guest access via CWA, including differentiation of hotspot, self-registration, and sponsored access flows
Operate post-onboarding workflows using the My Device Portal, including revocation of certificates and device de-registration for lost or stolen endpoints
Analyse how Cisco ISE collects endpoint data using built-in probes, device sensors, and pxGrid enrichment, and how each method contributes to the accuracy and coverage of profiling
Analyse how the profiling policies in Cisco ISE classify endpoints based on collection attributes, and how logical profiles are created and applied to support the decision-making process for determining access based on identity
Develop scalable profiling solutions through matching of design principles, probes, and NADs with different network conditions
Maintain visibility of the profiling process through dashboards and reports, and optimize the deployment process through optimizations
Maintain and monitor Cisco ISE policies for securing and complying with access to the network

Skills you'll learn

13 skills
Cisco ISE Administration
Network Access Control
Identity Management
Active Directory Integration
LDAP Integration
Authorization Policies
RADIUS Troubleshooting
Guest Access Management
Device Onboarding
Endpoint Profiling

Certificate

  • Attendance Certificate from CLS Learning Solutions
  • This course enables you to pass 300-715 SISE exam

Potential Career Paths

Network security engineers
Network administrators
Technical solution architects
Consulting security engineers