Project

General

Profile

Configuring Cisco ISE » History » Version 3

Luke Murphey, 12/03/2013 07:25 PM

1 1 Luke Murphey
h1. Configuring ISE
2 1 Luke Murphey
3 1 Luke Murphey
(thanks to Morten Nilsen for these instructions)
4 1 Luke Murphey
5 1 Luke Murphey
First, go to Policy, Policy Elements, Dictionaries
6 1 Luke Murphey
7 1 Luke Murphey
!ISE_Dictionaries.png!
8 1 Luke Murphey
9 1 Luke Murphey
Expand System, Radius and click RADIUS Vendors
10 1 Luke Murphey
11 2 Luke Murphey
!ISE_RADIUS_Vendor.png!
12 2 Luke Murphey
13 2 Luke Murphey
Click Add:
14 2 Luke Murphey
15 1 Luke Murphey
!ISE_Add_Vendor.png!
16 2 Luke Murphey
17 2 Luke Murphey
Enter the dictionary name and vendor ID in the form:
18 2 Luke Murphey
19 2 Luke Murphey
!ISE_Dictionary_Entry.png!
20 2 Luke Murphey
21 2 Luke Murphey
Hit submit
22 2 Luke Murphey
 
23 2 Luke Murphey
Open the newly created dictionary and select the dictionary attributes tab:
24 2 Luke Murphey
25 2 Luke Murphey
!ISE_Dictionary_Attribute.png!
26 2 Luke Murphey
27 2 Luke Murphey
Click Add again
28 2 Luke Murphey
29 2 Luke Murphey
Enter the attribute name groups and change Direction to OUT and ID of 1
30 2 Luke Murphey
31 2 Luke Murphey
!ISE_Attribute.png!
32 2 Luke Murphey
33 2 Luke Murphey
Hit Submit
34 2 Luke Murphey
 
35 2 Luke Murphey
Now navigate to policy elements/results
36 2 Luke Murphey
Expand Authorization and select the Authorization Profiles element
37 2 Luke Murphey
38 2 Luke Murphey
!ISE_Auth_Profile.png!
39 2 Luke Murphey
40 2 Luke Murphey
Click Add
41 3 Luke Murphey
Enter a name:
42 2 Luke Murphey
43 1 Luke Murphey
!ISE_Auth_Profile_Entry.png!
44 3 Luke Murphey
45 3 Luke Murphey
Under Advanced Attributes Settings, pick the newly created dictionary:
46 3 Luke Murphey
47 3 Luke Murphey
!ISE_Advanced_Attributes.png!
48 3 Luke Murphey
49 3 Luke Murphey
Enter the desired value in the text field:
50 3 Luke Murphey
51 3 Luke Murphey
!ISE_Advanced_Attribute_Settings.png!
52 3 Luke Murphey
53 3 Luke Murphey
You can now use this authorization profile in your authorization policy to grant users access to Splunk.