---
title: "Integrating Cisco ISE into NIOS"
canonical: "https://docs.infoblox.com/space/nios85/35752383/Integrating%20Cisco%20ISE%20into%20NIOS"
format: markdown
---
With the rapid growth of BYOD (Bring Your Own Device) trend, the complexity of securing network resources has become more challenging. To ensure data privacy and security of all network resources against threats, Infoblox introduces the **Ecosystem** feature that allows you to expand the visibility of networks, users, and devices. Using this feature improves overall IT operations by sharing information between network and security teams.  
Integrating Cisco ISE server into NIOS enables NIOS and Cisco ISE to exchange valuable network, user, device, and security-event information, enriching both Infoblox DDI and Cisco ISE data. Cisco ISE is a centralized security solution (Network Access Control) that automates and enforces context-aware security access to network resources. NIOS supports the integration of Cisco ISE versions 2.0, 2.2, 2.3, 2.4, 2.6, and 2.7. You can also publish DHCP lease and IPAM information for these Cisco ISE versions. This feature ensures that only the authorized users from legitimate devices get access to the services they need. Note that you can view the subscribed information from the IPAM tab and the IP Map panel. Make sure that you synchronize time between the managing member and Cisco ISE.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Cisco ISE does not support IPv6 addresses.


When you configure a Cisco ISE, you can do the following:

- **Subscribe** **to** **contextual** **data**: NIOS acts as a client to the Cisco ISE and collects information about the subscribed data types. You can configure extensible attributes without restricting them to specific object types, and then map these extensible attributes to Cisco ISE data to collect additional information. You can view subscribed information collected from the Cisco ISE in the appropriate tabs (**IPAM**, **IP** **Map** panel, and **Network** **Users**) of the Infoblox GUI. For information about how to subscribe to contextual data, see *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)*<span style="color: #0000ff">[Cisco](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)*<span style="color: #0000ff">[ISE](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)</span>* *<span style="color: #0000ff">[on](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)*<span style="color: #0000ff">[NIOS](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35881899) You can also monitor subscription data using the **Subscription** report. For information, see *<span style="color: #0000ff">[Subscription](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-SubscriptionData)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-SubscriptionData)*<span style="color: #0000ff">[Data](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-SubscriptionData)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-SubscriptionData)
- **Publish**** contextual**** data** - You can publish contextual data from NIOS to specific Cisco ISE based on the conditions and criteria specified in the notification rules. To publish RPZ and threat protection notifications, you must first set up an external syslog server, as described in *<span style="color: #0000ff">[Specifying](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)*<span style="color: #0000ff">[Syslog](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)*<span style="color: #0000ff">[Server](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)*<span style="color: #0000ff">[for](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)*<span style="color: #0000ff">[Notifications](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3377) For information about notification rules, see *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)*<span style="color: #0000ff">[Notification](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)*<span style="color: #0000ff">[Rules](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*. You can monitor published data using the **Publish ****Data** report through the Reporting and Analytics feature. For information about this report, see *<span style="color: #0000ff">[Publish](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-bookmark3163)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-bookmark3163)*<span style="color: #0000ff">[Data](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-bookmark3163)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081/About+Dashboards#AboutDashboards-bookmark3163)

# > Macro (anchor)

Administrative Permissions

By default, only superusers can add, edit, and delete Cisco ISEs. Limited-access admin groups can access Cisco ISEs only if their administrative permissions are defined. For information about administrative permissions, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)</span>* *<span style="color: #0000ff">[Administrative](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)*<span style="color: #0000ff">[Permissions](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979376)</span>*.

# > Macro (anchor)

> Macro (anchor)

Prerequisites to Integrate Cisco ISE with NIOS

Do the following before you begin using this feature on NIOS:

- You must install the **Network** **Insight** license to configure Cisco ISE. You might need the following licenses to configure notification rules for RPZ and threat protection event types:
  For information about how to install licenses, see *<span style="color: #0000ff">[Managing](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35417954)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35417954)*<span style="color: #0000ff">[Licenses](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35417954)</span>*.
- Cisco ISE uses SSL certificates as the method of authentication. You must upload the client certificate and client key when configuring the Cisco ISE server. You can include both client certificate and key in a single file and then upload. For information, see *<span style="color: #0000ff">[Generating](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478980)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478980)*<span style="color: #0000ff">[Certificates](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478980)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478980)

- For the bulk download certificate, download the server certificate from the monitoring node. If the admin node and monitoring node are on one node, then download the certificate from the admin node.  
Log into Cisco ISE and download the default self-signed server certificate (**Administration** -> **System** -> **Certificates** -> **Export**).

- For the CA certificate, download the CA certificate from the admin node or the self-signed certificate (**Administration** -> **System** -> **Certificates** -> **Export**).
- Register NIOS as a client on the Cisco ISE. You must enable the **Auto-Registration** option on the Cisco ISE: From the **Administration** menu -> click **pxGrid**** Services**, and then click **Enable ****Auto-Registration**. For more information, refer to Cisco ISE documentation. When you register NIOS successfully, you can view infoblox_client_subscribe_xxxx and infoblox_client_publish_xxxx, where xxxx is a number generated based on the IP of the subscribing member on the Cisco ISE. If auto-registration is not enabled, approve the pxGrid client after registration. If you change the certificates, Cisco ISE may not register the client successfully. In this case, delete the related pxGrid client from the Cisco ISE server, which is automatically created again.
- Enable the Identity Mapping feature on the NIOS appliance:

> Macro (legacy-content)

> Macro (legacy-content)

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Refer to Cisco ISE documentation for information about how to perform auto-registration, creating authorized groups, and approving dynamic topics.

# Limitations of Integrating Cisco ISE with NIOS

Integrating Cisco ISE with NIOS has the following limitations:

- You can publish IPAM data only from the Grid Master that is a subscribing member. A subscribing member is a Grid member that you want to subscribe as the client on the Cisco ISE. For more information, see <span style="color: #0000ff">*[Publishing Data](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359)*</span>[. ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359)
- Only the subscribing member can publish its data to Cisco pxGrid.
- <span style="color: #000000">If the Grid Master is the subscribing member and you promote a Grid Master candidate to the Grid Master, then you have to create a client certificate for the promoted Grid Master.</span>

# Generating Certificates

To generate a self-signed key and certificate:

1. openssl genrsa -out self1.key 4096
2. openssl req -new -key self1.key -out self1.csr
3. openssl req -x509 -days 365 -key self1.key -in self1.csr -out self1.cer

`For CSR request:`

`Country Name (2 letter code) [XX]: <Country Name>, for example: US`

`State or Province Name (full name) []: <State Name>, for example: CA`

`Locality Name (eg, city) [Default City]:<City Name>, for example: SC`

`Organization Name (eg, company) [Default Company Ltd]:<Company Name>, for example Infoblox`

`Organizational Unit Name (eg, section) []:<Organization Name>, for example: QA`

`Common Name (eg, your name or your server's hostname) []:<host name of the subscribing member>`

`Email Address []:`

Enter the following 'extra' attributes to be sent with your certificate request:

`A challenge password []:`

Import the certificate generated in step 3 to Cisco ISE's trusted store. Select the **Trust for authentication within ISE** checkbox.

Export the self-signed ISE certificate of the ISE server (under System -> Certificates). Make sure to select the** pxGrid: Use certificate for the pxGrid Controller **checkbox before exporting it.

You can call this as isemnt.cert

Wait for ISE services to restart. It may take a few minutes.