08-22-2023 06:38 AM - edited 08-22-2023 07:30 AM
Dear Experts,
I have a query pertaining to the integration of Cisco ISE and Microsoft Active Directory (AD). Our client operates four domains within four separate forests within the same environment, making trust relationships between them possible. Companies A (ShareService - companya.com), Company B (companyb.com), Company C (companyc.com), and Company D (companyd.com) are isolated from one another. Company A is able to establish trust relationships with the other companies, whereas Companies B, C, and D do not.
My questions are the following:
1. Is it possible for a single instance of Cisco ISE to integrate with multiple domains across different forests? In other words, can companya.com, companyb.com, companyc.com, and companyd.com all connect to Cisco ISE to import AD security groups from their respective AD Servers? The reference documentation "Prerequisites for Integrating Active Directory and Cisco ISE" appears to support this for version 2.0. However, I am unable to locate equivalent information for ISE 3.0.
2. If multiple domain integration across different forests is not supported, what alternative solutions are available? I would greatly appreciate your professional insights and recommendations on this matter.
Thank you for your assistance.
Solved! Go to Solution.
08-22-2023 03:56 PM
Maximum Active Directory forests (Join Points) |
50 |
08-22-2023 04:01 PM
ISE supports up to 50 Active Directory Join Points.
We call them join points because you may join forests, domains, and even skip levels of directories if necessary to work around AD bloat and mismanagement.
To find Prerequisites for Integrating Active Directory and Cisco ISE for ISE 3.3 (our latest version), I did an explicit internet search on ise 3.3 "Prerequisites for Integrating Active Directory and Cisco ISE" and followed the #1 hit for Cisco Identity Services Engine Administrator Guide, Release 3.3 then searched the page with my browser for the word "prerequisite".
Yes, it's supported.
08-22-2023 03:56 PM
Maximum Active Directory forests (Join Points) |
50 |
08-22-2023 04:01 PM
ISE supports up to 50 Active Directory Join Points.
We call them join points because you may join forests, domains, and even skip levels of directories if necessary to work around AD bloat and mismanagement.
To find Prerequisites for Integrating Active Directory and Cisco ISE for ISE 3.3 (our latest version), I did an explicit internet search on ise 3.3 "Prerequisites for Integrating Active Directory and Cisco ISE" and followed the #1 hit for Cisco Identity Services Engine Administrator Guide, Release 3.3 then searched the page with my browser for the word "prerequisite".
Yes, it's supported.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide