cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
493
Views
0
Helpful
1
Replies

Cisco ISE guest internet controlled access with PAN integration

ymadheka
Level 4
Level 4

Hi Team,

We are working on an oppurtunity of Cisco ISE at Lupin pharma where the customer is currently using Palo Alto.

The requirement of the customer is to have the guest access management done by the ISE but at the same time integrate with PAN for the controlling internet access of the guest users via PAN. There is a known integration of our ISE with PAN as documented here:

https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295

But the use case here is that the guest user should be populated to either of two groups namely high privilege and low privilege which will be mapped in the PAN policy with Strict and light URL Filtering policy.

Is this possible to have ISE synchronize the group with the guest user details automatically with policy to be applied only as group and not user ID.

  
Warm Regards,
Yogesh Madhekar

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

There is currently no such integration

Please ask PAN to consume our context via pxgrid and start supporting Scalable group tags as well

Checkpoint has integrated already for this use case

View solution in original post

1 Reply 1

Jason Kunst
Cisco Employee
Cisco Employee

There is currently no such integration

Please ask PAN to consume our context via pxgrid and start supporting Scalable group tags as well

Checkpoint has integrated already for this use case