---
title: "Introduction"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDIntegrationCiscoISE/1544651237/Introduction"
format: markdown
---
This solution integrates Infoblox Threat Defense<sup>TM</sup>  with Cisco Identity Services Engine (ISE) to deliver automated, policy-driven **threat response** based on DNS threat intelligence (Threat Feeds and SOC Insights). Cisco ISE serves as a centralized **Network Access Control **(NAC**)** platform that enforces dynamic access policies across the network. By leveraging Cisco ISE’s RESTful APIs, Infoblox Threat Defense<sup>TM</sup> can programmatically quarantine endpoints that exhibit malicious behavior, as detected through DNS query analysis.

When a DNS query from an endpoint is flagged as **a threat** by Infoblox or leads to the generation of SOC Insights, an event is triggered that initiates an API call to Cisco ISE, placing the endpoint into a quarantine VLAN or applying a restrictive access policy. This event-driven quarantine mechanism significantly reduces response time and limits potential lateral movement of threats within the network. The solution also supports scheduled de-quarantine workflows, allowing endpoints to be automatically removed from quarantine after a predefined investigation period, thereby streamlining incident response and recovery.