Overview
The Implementing and Configuring Cisco Identity Services Engine (SISE) training teaches you to deploy, configure and operate Cisco Identity Services Engine as the central platform for identity-based access control. Learning begins with core architecture and installation, then progresses through network access control, identity stores, policy design and day-to-day operations.
You will configure authentication and authorization policies, create scalable guest onboarding workflows, integrate network devices and apply identity-based access decisions across wired and wireless environments. The course also covers endpoint profiling, posture assessment, TACACS+ device administration, TrustSec concepts, certificate management, lifecycle operations and advanced administration practices.
Hands-on labs cover Cisco ISE personas, certificate-based authentication, TEAP, BYOD onboarding, device profiling, guest services and policy enforcement. The training prepares you for the 300-715 SISE v1.1 exam, supports the Cisco Certified Specialist – Security Identity Management Implementation certification, satisfies a CCNP Security concentration exam requirement and earns 32 Continuing Education credits toward recertification.
What You Will Learn
- Gain hands-on experience configuring, deploying and operating Cisco ISE for identity-based access control.
- Design secure authentication, authorization, guest access and BYOD onboarding policies for wired and wireless networks.
- Integrate Cisco ISE with Active Directory, LDAP and network devices, including endpoint profiling and compliance-based controls.
- Troubleshoot authentication and policy issues using labs, logs and reporting tools.
- Prepare for the 300-715 SISE v1.1 exam.
Who Should Enrol
- Network security engineers
- Network administrators
- Consulting security engineers
- Technical solutions architects
- Network managers
- Sales engineers
- Account managers
Course Outline
View syllabus
1. Cisco ISE Evolution, Foundation and Role
2. Architecture and Design
3. Cisco ISE Installation and Initial Configuration
4. 802.1X in Cisco ISE
5. MAB in Cisco ISE
6. Network Device Integration with Cisco ISE
7. Identity Sources and Authentication Types
8. Active Directory and LDAP Integration
9. Identity Selection and Resolution Logic
10. Cisco ISE Policy Framework
11. Authentication Policies
12. Authorization Policies
13. Troubleshoot Policies and Sessions
14. Guest Access Overview
15. Guest Access Policies and Settings
16. Guest Portals and Lifecycle Operations
17. Sponsor Portals
18. BYOD Architecture and Use Cases
19. BYOD Onboarding with Native Supplicant Provisioning
20. BYOD Lifecycle Operations
21. Profiling Architecture and Capabilities
22. Probes and Data Collection
23. Profile Policies and Authorization
24. Profile Monitoring and Design
25. Posture Service Flow and Agents
26. Posture Updates and Client Provisioning
27. Posture Policies and Compliance-Based Access
28. Posture Testing and Monitoring
29. AAA and TACACS+
30. TACACS+ Device Administration
31. TACACS+ Command Authorization
32. Cisco TrustSec Overview
33. Cisco TrustSec in Cisco ISE
34. Cisco ISE Administration
What to Expect in the Exam
- Architecture and deployment
- Policy enforcement
- Web authentication and guest services
- Profiler
- BYOD
- Endpoint compliance
- Network access device administration
Prerequisites
- Familiarity with the Cisco IOS Command-Line Interface for wired and wireless network devices.
- Familiarity with Cisco Secure Client.
- Familiarity with Microsoft Windows operating systems.
- Familiarity with 802.1X.
- Recommended learning offering: Implementing and Operating Cisco Security Core Technologies (SCOR).
Detailed Course Objectives
- Describe how Cisco ISE fits into contemporary network security architectures, including its main functions, design motivations and common use cases.
- Examine Cisco ISE node personas, supported deployment models, licensing considerations and their design and scalability implications.
- Implement installation workflows, platform requirements and initial setup for Cisco ISE on supported virtual and hardware platforms.
- Evaluate 802.1X network access principles, message flow and authorization outcomes across wired and wireless environments.
- Describe how MAC Authentication Bypass (MAB) works, including fallback behavior, flow sequence and policy application for non-802.1X-compatible devices.
- Establish the role of network access devices in Cisco ISE authentication workflows and configure them for secure policy enforcement.
- Discuss internal and external identity sources, user and device identity management and certificate-based authentication.
- Integrate Cisco ISE with Active Directory and LDAP for external user authentication.
- Interpret identity source selection, identity store sequences, fallback behaviour and identity normalization.
- Explain Cisco ISE policy sets and the relationship between global and local authentication and authorization logic.
- Identify how Cisco ISE evaluates authentication policies using rule conditions, identity store sequences and dictionaries.
- Interpret how Cisco ISE applies authorization policies using Conditions Studio and user and device attributes.
- Analyze logs, RADIUS flow data and session context to troubleshoot authentication and authorization issues.
- Analyze web-based guest access using Central Web Authentication and compare hotspot, self-registration and sponsored flows.
- Establish global guest settings for account lifecycle, credential policies, communication methods and access types.
- Configure guest portals, account lifecycles and scalable deployment models.
- Configure sponsor-driven guest access, sponsor groups, guest types and portal behaviour.
- Explain Cisco ISE architecture and policy controls for secure, scalable BYOD access.
- Configure Cisco ISE to deliver supplicants, issue certificates and enforce BYOD onboarding policies.
- Operate My Device Portal workflows, including certificate revocation and device de-registration.
- Explain endpoint profiling architecture, components, data flows and feed services.
- Analyze endpoint data collection using built-in probes, device sensors and pxGrid enrichment.
- Analyze profiling policies, logical profiles and identity-based authorization.
- Design scalable profiling solutions using appropriate probes and network device integration.
- Use dashboards and reports to maintain profiling visibility and optimize deployments.
- Explain posture services, agent types, flow logic, operational modes and use cases.
- Configure posture agent delivery, update services, portals and delivery policies.
- Administer Cisco ISE policies for secure and compliant network access.
- Test compliance-based enforcement using Cisco AnyConnect endpoint scenarios.
- Interpret posture outcomes, session behaviour and reporting tools.
- Explain TACACS+ device administration, AAA concepts and the differences between TACACS+ and RADIUS.
- Configure TACACS+ command sets, profiles and policy sets.
- Onboard network devices and configure authentication and authorization rules for administrator access.
- Implement advanced TACACS+ command authorization and scalable device administration.
- Compare Cisco TrustSec architecture, operation and enterprise design considerations.
- Configure Cisco TrustSec segmentation using SGT classification, SXP propagation and tag-based enforcement.
- Operate Cisco ISE through maintenance, backup and restore, certificate management and structured upgrades.
Lab Outline
- Explore the initial Cisco ISE configuration, GUI and system certificate.
- Configure network device groups and network devices.
- Integrate Cisco ISE with Active Directory.
- Configure MAB.
- Configure wired 802.1X.
- Configure wireless 802.1X and optional wired EAP-TLS and TEAP.
- Troubleshoot Cisco ISE 802.1X configuration errors.
- Configure hotspot guest access.
- Configure sponsored guest access.
- Configure BYOD.
- Manage BYOD devices.
- Configure profiling.
- Configure authorization policy rules and run profiler reports.
- Configure posture preparations and client provisioning.
- Configure posturing and reporting.
- Configure TACACS+ basic device administration.
- Configure TACACS+ command authorization.
- Configure Cisco TrustSec.
- Configure secure Syslog with TLS v1.3 and install a Cisco ISE patch.