Cisco Cisco Identity Services Engine 1.3 릴리즈 노트

다운로드
페이지 80
 
16
Release Notes for Cisco Identity Services Engine, Release 1.3
 
  New Features in Cisco ISE, Release 1.3
Support for OVA Installation on Virtual Machines
Virtual machine installations are now simplified. This release supports OVA template installation. You 
can use the OVA template for easier and more rapid deployments of the virtual machine installation for 
Cisco ISE, Release 1.3. 
Cisco pxGrid Services
Cisco pxGrid is used to enable the sharing of contextual-based information from Cisco ISE session 
directory to other policy network systems such as Cisco Adaptive Security Appliance (ASA). The 
pxGrid framework can also be used to exchange policy and configuration data between nodes like 
sharing tags and policy objects between ISE and third party vendors, and for non-ISE related information 
exchanges such as threat information. You can enable the pxGrid Services from the Administration > 
Deployment 
page.
Cisco pxGrid Identity Mapping 
The pxGrid Identity Mapping option enables you to monitor users that are authenticated by a Domain 
Controller (DC) and not by Cisco ISE, when Cisco pxGrid services are used. In networks where Cisco 
ISE does not actively authenticate users for network access, it is possible to use Identity Mapping to 
collect user authentication information from the active directory (AD) Domain Controller. Identity 
Mapping collects session information from the domain controller similar to Context Directory Agent 
(CDA). For more information on CDA, refer to 
You can configure Identity Mapping by navigating to Administration > pxGrid Identity Mapping > 
AD Domain Controllers
.
AnyConnect Unified Agent
Posture Assessment can be performed using the AnyConnect ISE Agent or using the NAC Agent. You 
can install AnyConnect ISE Agent or NAC Agent by using the client provisioning policy (CPP) 
configuration in Cisco ISE.
You can add the AnyConnect Agent from Policy > Policy Elements > Results > Client Provisioning > 
Resources
.
Multi-Forest Active Directory
Cisco ISE 1.3 supports Multi-Forest/Multi-Domain integration with Active Directory infrastructures to 
support authentication and attribute collection across large enterprise networks. Cisco ISE 1.3 supports 
up to 50 domain join points. You can perform more operations with Active Directory in Cisco ISE 1.3. 
Refer to 
 for more information.