---
title: "Configuring Cisco ISE on NIOS"
canonical: "https://docs.infoblox.com/space/nios85/35881899/Configuring%20Cisco%20ISE%20on%20NIOS"
format: markdown
---
You can configure the supported versions of Cisco ISE servers on the NIOS appliance. You can subscribe for identity information that you wish to collect from the Cisco ISE, such as user name, domain name, VLAN, session state, SSID, endpoint profile, and security group. You can also add extensible attributes without restricting it to specific object types, and map these extensible attributes with the Cisco ISE field types to collect additional information. Note that you can subscribe to only one Cisco ISE per member and each member can subscribe to only one Cisco ISE. You can publish ADP and RPZ notifications, DHCP and IPAM information from NIOS to Cisco ISEs based on the notification rules that you have configured. 

<span style="color: #000000">For information about supported Cisco ISE versions to publish DHCP lease and IPAM information, see </span>[*<span style="color: #000000">Integrating Cisco ISE into NIOS</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35752383)<span style="color: #000000">.</span>

> ⚠️ The procedures in the sections below is for configuring Cisco pxGrid 1.0. For instructions on configuring Cisco pxGrid 2.0, see [*Configuring Outbound Endpoints*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35752344).

# > Macro (anchor)

> Macro (anchor)

Configuring Cisco ISE Servers

You can configure a Cisco server either by using the **Ecosystem **-> **Cisco ISE Endpoint** tab or by using the **Ecosystem **<span style="color: #172b4d">-></span> **Outbound Endpoint **<span style="color: #172b4d">-></span> **Add **<span style="color: #172b4d">-></span> **Add Cisco ISE Endpoint** option. This section describes how to configure a Cisco server using the **Ecosystem **<span style="color: #172b4d">-> </span>**Cisco ISE Endpoint**<span style="color: #172b4d"> tab</span>. For information about using the **Add Cisco ISE Endpoint**<span style="color: #172b4d"> option</span>, see [*Configuring Outbound Endpoints*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35752344).

To configure a Cisco ISE server:

1. From the **Grid** tab, select the **Ecosystem** tab -> **Cisco ISE Endpoint** tab, and then click the Add icon.   
or  
From the **Grid** tab, select the **Ecosystem** tab, and click **Add** **Cisco** **ISE** from the Toolbar.
2. In the *Add* *Cisco* *ISE* wizard, complete the following.
  - **Server** **Address**: Enter the IP address of the Cisco ISE.
  - **Version**: Select the version of the Cisco ISE.
  - **Subscribing** **Member**: Click **Select** to select a Grid member that you want to subscribe as the client on the Cisco ISE. In the *Member* *Selector* dialog box, select a Grid member from the list. This member interacts with the Cisco ISE to obtain contextual information for the subscribed data types.
  - **Network** **View**: This appears only when you have multiple network views. From the drop-down list, select the network view in which you want to create the network.
  - **Client** **Certificate**: Click **Select** to upload the client certificate. In the *Upload* dialog box, click Select to navigate to the certificate, and then click **Upload**.
  - **Bulk** **Download** **Certificate**: Click **Select** to download the server certificate from the monitoring node or self-signed certificate.
  - **Manage** **Certificates**: Click **CA** **Certificates** to upload the self-signed certificate or CA certificate. In the *CA* *Certificates* dialog box, click the Add icon, and then navigate to the certificate to upload it.
  - **Test** **Credentials**: Click this to validate the Cisco ISE configuration before proceeding. When you click Test Credentials, the appliance validates the certificates.
  - **Comment**: Enter additional information about the configuration.
  - **Disabled**: Select this if you want to save the configuration but do not want to use it yet. You can clear this checkbox when you are ready to use this Cisco ISE.

3. Click **Next** to specify the data types that you are interested to obtain from the Cisco ISE. The Cisco ISE shares information only for the subscribed data types. Complete the following to specify data types you want to collect from the Cisco ISE:

> Macro (legacy-content)

4. Click Next to add extensible attributes to the Cisco ISE. For information, see <span style="color: #0000ff">[*Managing*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span><span style="color: #0000ff">[* Extensible*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span><span style="color: #0000ff">[* *](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span><span style="color: #0000ff">[*Attributes*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span>.

5. Save the configuration.

# > Macro (anchor)

> Macro (anchor)

Modifying Cisco ISE Configurations

You can select data types that need to be published from NIOS to Cisco ISE after you have configured the Cisco ISE. You can modify the Cisco ISE configurations, as follows:

1. From the **Grid** tab, select the **Ecosystem** tab -> **Cisco** tab, click the **Action** icon next to the server name and select **Edit** from the menu.
2. The *Cisco* *ISE* *Server* editor provides the following tabs from which you can modify data:
  - **General**: You can modify data in this tab as described in *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)*<span style="color: #0000ff">[Cisco](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)*<span style="color: #0000ff">[ISE](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)*<span style="color: #0000ff">[on](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)*<span style="color: #0000ff">[NIOS](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26479004)
  - **Subscription**: You can edit data types that you have subscribed. You can use the arrows to move data types from the **Available** **Data** **Type** table to the **Selected** **Data** **Type** table and vice versa. The appliance receives information for all data types in the **Selected** **Data** **Type** table and extensible attributes that are configured.
  - **Publication**: To publish dynamic data from NIOS, you must first configure notification rules, as described in *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)*<span style="color: #0000ff">[Notification](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)*<span style="color: #0000ff">[Rules](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35882359/Publishing+Data#PublishingData-bookmark3378)</span>*. You can add data types that you want to publish to Cisco ISE server by using the arrows to move data types from the **Available** table to the **Selected** table and vice versa. The appliance publishes information only for the data types that are added in the **Selected** table.
  - **Extensible** **Attributes**: You can add, modify, and delete extensible attributes that are associated with the Cisco ISE server. For information, see *<span style="color: #0000ff">[Managing Extensible](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)*<span style="color: #0000ff">[Attributes](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448912)</span>*.
3. Save the changes.

# > Macro (anchor)

> Macro (anchor)

Overriding Subscription Settings

You can override subscription settings and mapped extensible attributes at the network container, network, and DHCP range levels. By default, networks inherit subscription settings from those configured while adding the Cisco server. You can override these settings and subscribe new values at the DHCP range, network container, or network level. A network inherits subscription settings from its parent object. If you override the values at the network container level, then the network inherits the network container values. Otherwise, the network continues to inherit the values configured from the Cisco ISE. A shared network without a parent network container continues to inherit settings from the Cisco ISE.  
To override an inherited value, click **Override** next to it and complete the appropriate fields. When you click **Override**, the appliance displays the value inherited from its parent object (if any).  
To override subscription settings and mapped extensible attributes:

1. **Network** **Level**: From the **Data** **Management** tab, select the **DHCP** tab -> **Networks** tab -> **Networks** -> *network* checkbox, and then click the Edit icon.  
**Network** **Container**: From the **Data** **Management** tab, select the **IPAM** tab -> *network_container* checkbox, and then click the Edit icon.  
**DHCP** **Range** **Level**: From the **Data** **Management** tab, select the **DHCP** tab -> **Networks** tab -> **Networks** -> *network* ->* addr_range* checkbox, and then click the Edit icon.
2. In the *Network* *or* *Range* editor, click **Toggle** **Advanced** **Mode** if the editor is in basic mode, and then click the Cisco ISE tab.
3. Save the configuration and click **Restart** if it appears at the top of the screen.

# > Macro (anchor)

> Macro (anchor)

Viewing Identity Mapping Information

To view user information, you must first enable identity mapping feature at the Grid level. For information about enabling Identity Mapping feature, see *<span style="color: #0000ff">[Enabling](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278/Viewing+Identity+Mapping+Information#ViewingIdentityMappingInformation-bookmark1304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278/Viewing+Identity+Mapping+Information#ViewingIdentityMappingInformation-bookmark1304)*<span style="color: #0000ff">[Identity](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278/Viewing+Identity+Mapping+Information#ViewingIdentityMappingInformation-bookmark1304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278/Viewing+Identity+Mapping+Information#ViewingIdentityMappingInformation-bookmark1304)*<span style="color: #0000ff">[Mapping](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278/Viewing+Identity+Mapping+Information#ViewingIdentityMappingInformation-bookmark1304)</span>*.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ You do not need an **MS****Management** license to enable the identity mapping feature.

You can view user information in the **Network** **Users** tab. For more information, see *<span style="color: #0000ff">[Viewing](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)*<span style="color: #0000ff">[Identity](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)*<span style="color: #0000ff">[Mapping](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)</span>* *<span style="color: #0000ff">[Information](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35785278)</span>*.

# > Macro (anchor)

> Macro (anchor)

Deleting Cisco ISE Servers

When you delete a Cisco ISE, the appliance moves it to the Recycle Bin, if enabled. You can later restore it if needed. To delete a Cisco ISE server:

1. From the **Grid** tab, select the **Ecosystem** tab > **Cisco** tab -> *Cisco* *ISE* *server* checkbox, and then click the Delete icon.
2. In the *Delete* *Confirmation* dialog box, click **Yes** to delete the Cisco ISE server.