Networking-Forums.com

Professional Discussions => Security => Topic started by: LynK on October 12, 2016, 01:02:45 PM

Title: Cisco ISE 2.1 (any takers?)
Post by: LynK on October 12, 2016, 01:02:45 PM
Hey guys,

Any of you guys upgrade ISE to 2.1 yet? What are your thoughts/concerns. We have to upgrade because 2.0.0.306 does not support windows 10/windows phone/later releases of android authentication.

Any of you on 2.1.0.474? How is it? Did they fix a lot of the TACACS+ junk? I did not much in the release notes.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: deanwebb on October 12, 2016, 04:01:28 PM
No ISE here, sorry. We're a CounterACT shop. But we've had Win10 support for over a year.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: LynK on October 13, 2016, 08:22:19 AM
please do not rub it in. Not to mention the TACACS issues on the current version we are on. Oh... and one more thing. It takes roughly 4 hours per box to do an upgrade.... sigh.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: deanwebb on October 13, 2016, 12:08:25 PM
Well, going from 32-bit to 64-bit on CounterACT is a 24-hour long process. Ugh. And I have to call in about a box that went berzerk after having a RAM dump... and zero TACACS with CounterACT, although we've asked for it as a feature...
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: LynK on October 13, 2016, 02:50:52 PM
yeah.... its frustrating, but oh well.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: deanwebb on October 13, 2016, 08:11:29 PM
Funny thing is, working with NAC is kinda job security, provided you know how to get other teams on your side. Social networking is VERY important with doing NAC stuff.

Has Cisco helped provide you with stuff so you can lab out your NAC environment? You should have a dev and a pre-production lab, given all the mayhem NAC can cause when it gets angry.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: mlan on October 17, 2016, 03:29:32 PM
This thread is not helping me feel good about ISE 2.x.  Is it worth upgrading at this point just to migrate TACACS+ over?
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: deanwebb on October 18, 2016, 11:05:07 AM
ACS 5 is out and does the job. I'm pressing for ForeScout to include TACACS+ in future versions.
Title: Re: Cisco ISE 2.1 (any takers?)
Post by: LynK on October 19, 2016, 01:41:02 PM
I cannot confidently recommend ISE to anyone who is looking to do TACACS. We are having a few issues, and until we know all of them are fixed I would try to use ACS.