
Introduces Cisco ISE as a centralized security policy platform that provides identity and context, enabling AAA, posture, profile, guest access, BYOD, and dynamic VLAN-based segmentation with pxGrid integration.
Explore Cisco ISE 2.7 use cases for secure guest access, isolated wired and wireless networks, and posture-driven access. See asset visibility, profiling, BYOD support, and dynamic segmentation enabling policy enforcement.
Learn to install Cisco ISE 2.7 on VMware Workstation using the ova file, with a 90-day evaluation license and guided initial setup.
Learn to install Cisco ISE on Eve-NG or GNS3, configure storage and images, copy files, and perform the initial CLI setup for ISE.
Learn how to install Cisco ISE 2.7 on VMware ESXi using an OVA file, configure storage, network, evaluation deployment, and complete setup with hostname, IP, DNS, and SSH.
Explore Cisco ISE CLI basics, exec and configuration modes, essential show and management commands, and practical tips for ssh access, password resets, and application status.
Configure a two-node Cisco ISE topology with primary and secondary ISE, switches, and a Windows Server 2012 for FTP, DNS, DHCP, NTP, and certificate services.
Install and configure Active Directory on a Windows server, promote it to a domain controller for test.local, and create an organizational unit structure with example users and groups.
Configure a DNS server for active directory by creating forward and reverse lookup zones, add host records for ise1 and ise2, and verify resolution with nslookup.
Install and configure a dhcp server on Windows Server, activate dhcp, and create four scopes for vlan 10, 20, 30, and 40 with 192.168.x.x addresses, gateway, and dns settings.
Configure Windows Server 2012 as an ntp server using group policy editor and time services, enable ntp, set the announce flag to 5, and verify with ntp tool or ndp.
Install, configure, and verify a certificate authority server using Active Directory Certificate Services, including enterprise and root CAs, sha-256 keys, web enrollment, and testing with Cisco ISE lab scenarios.
Learn to set up an FTP server for backup and restore of Cisco ISE pages, configuring FTP in IIS, and testing with a test file.
Configure switch one and switch two with vlans ten, twenty, thirty, forty, and hundred, set up trunking, and enable ip routing to test and verify vlan connectivity.
Configure, test, and verify an edge router to enable internet access by setting up interfaces, dns, nat inside/outside, aclS, and a default route, then validate connectivity and name resolution.
Configure two ISE nodes by running setup, setting hostnames eyes one and eyes two, IPs, DNS, and time zone, enabling SSH, and verifying connectivity by pinging gateway and name server.
Configure and verify a virtual wireless LAN controller (wlc) by setting system name, admin credentials, management and dhcp interfaces, mobility, ssid, and web access, then enable http/https and verify connectivity.
Learn how the Cisco ISE 2.7 dashboard presents dashlets for system summary, endpoints, and network devices, and how to customize layouts and navigate policy and administration.
Explore Cisco ISE basics: defining identity and identity stores, internal and external identities, local endpoints, and how nodes, personas, and services enable authentication, authorization, and policy management.
Cisco ISE defines four personas—policy service node, administration node, monitoring node, and pxGrid controller—each delivering distinct services; admin and monitoring can be primary/secondary, PSN runs actively.
Explore Cisco ISE licensing, comparing traditional and smart licenses, base plus device administration and VM licenses, and how standalone and distributed deployments affect licensing in ISE 2.7.
Learn how certificates prove identity and secure Cisco ISE communications, covering admin, EAP, portal, pxgrid, and radius dtls certificates, as well as wildcard, system, and trusted CA concepts.
Guide certificate enrollment for Cisco ISE, configure a CA, import trusted certificates, generate a multi-use certificate for ISE nodes, and validate browser trust after system restart.
Learn how to integrate Cisco ISE with Active Directory to enable user and machine authentication, and verify essential prerequisites like domain credentials, admin privileges, time sync, and DNS connectivity.
Configure and verify Cisco ISE 2.7 integration with Microsoft Active Directory by joining AD, retrieving groups, and defining an identity source sequence on ISE 1 and ISE 2.
Explore Cisco ISE deployment models from standalone single-box labs to scalable distributed deployments in small, medium, and large networks, detailing PAN, MMT, PSN, and pxGrid roles.
Learn to configure Cisco ISE high availability deployment by promoting ISE-1 to primary, joining ISE-2 as secondary, and validating prerequisites such as same version, DNS, hostnames, and trusted certificates.
Configure and verify an FTP repository in Cisco ISE using GUI for persistence across all deployment nodes, or CLI for local, temporary repositories, with validation and testing.
Learn to locate, download, verify MD5 checksums, and install the latest Cisco ISE patches in standalone and distributed deployments, then verify with show version and patch management tools.
Perform on-demand and scheduled backups of Cisco ISE. Learn to restore backups across primary, high availability, and standalone deployments using CLI or GUI, with certificate authority considerations.
Configure and verify configuration data backup and operational data backup in Cisco ISE using GUI, FTP repository, and encryption keys, then schedule automated backups and verify via CLI.
Learn to restore a Cisco ISE backup by selecting the configuration backup, confirming with the restore key, and verifying progress with show restore status as the system reboots.
Export and import certificates for Cisco ISE using GUI and CLI. Back up certificates and private keys separately from configuration using the ISE CLI.
Upgrade Cisco ISE from 2.7 to version 3 by applying latest patches, downloading the upgrade bundle, verifying hashes, and performing a split upgrade on a standalone device.
Learn how to configure Cisco ISE admin access with internal authentication, robust password and account policies, and RBAC-based menu and data access controls for admin groups.
Log in to Cisco ISE using Active Directory groups, map those groups to RBAC policies, and enable centralized administration with admin and read-only access.
Join a Windows 10 PC to the Active Directory domain test.local by changing the computer name, entering the domain, and rebooting; verify login with domain users.
Explain how IEEE 802.1X wired authentication uses EAP over LAN to secure port-based access in wired networks, with supplicant, authenticator, and authentication server, and radius-based authentication via Cisco ISE.
Identify the dot1x components—supplicant, authenticator, and authentication server—and describe how end devices like PCs or tablets are authenticated via a switch, Radius/ISE, and an Active Directory identity source.
Explore 802.1x port states auto, force authorized, and force unauthorized, and learn how authentication via eapol governs port authorization on switches.
Explore 802.1X operating modes: single host, multi host, multi domain, and multi authentication, showing how authentication on a port with MAC addresses and access control shapes network access.
Configure and verify Cisco ISE 2.7 IEEE 802.1X wired lab by deploying radius servers, policy sets, and domain/non-domain client authentication on switch ports.
Discover how downloadable ACLs from Cisco ISE automatically download to access layer switches, providing a single-point policy to dynamically restrict user access after authentication.
Demonstrates configuring and verifying downloadable ACLs with Cisco ISE 2.7 to restrict contractor access while allowing employees broad access, using dot1x, policy sets, and authorization profiles.
Explore dynamic VLANs in Cisco ISE 2.7, and see how authentication-based policies automatically assign endpoints to specific VLANs, replacing static port configurations for both wired and wireless access.
Configure and verify dynamic VLAN assignment with Cisco ISE 2.7, mapping employee and contractor users to VLAN 10 and VLAN 20 via decals and authorization policies, and validate through testing.
Explore certificate-based authentication for user and machine on PC one, using user and computer templates, group policies, dot1x, and ISE policy sets with Active Directory and certificate services.
Create two certificate templates in the certificate authority for user and workstation authentication, duplicating templates, configuring security and subject name, enabling auto enrollment, and issuing them.
Enable certificate services client auto enrollment for computer and user configurations by editing the default domain policy and enabling auto enrollment under the public key policy.
Create an IEEE 802.1X client group policy on Windows Server to enable certificate-based authentication using smartcard and other certificates, configuring user and computer authentication.
This lab demonstrates configuring certificate based authentication with Cisco ISE 2.7, including certificate profiles, identity source sequences, EAP-TLS, downloadable ACLs, and machine and user authorization verification.
Explore how Mab uses a device mac address as the credential, with switches dropping traffic until the first frame is learned and sent to Cisco ISE via radius.
Configure mab as a fallback when dot1x is unavailable, register endpoints in the internal identity store, and verify map-based access on a Cisco ISE 2.7 lab.
Learn how Cisco ISE easy connect provides port-based network access without a supplicant, using passive identity and Active Directory to grant limited access initially and full access after authorization changes.
Configure and verify Cisco ISE easyconnect passive ID lab across two nodes, integrating Active Directory via WMI and deploying ACLs and policies for easyconnect, employee, and contractor.
Explore policy sets in Cisco ISE, including network access and device administration, and learn how authentication and authorization rules are organized under a unified policy set.
Explore authentication policies in ISE, from policy sets and conditions to hits and actions, including reject, drop, and continue through radius, then proceed to authorization.
Explain authorization policies that apply after authentication, detailing conditions, profiles, and security groups for network and device access; differentiate local, global, and regular exceptions and their evaluation order.
Master condition studio in Cisco ISE 2.7 to create, save, and reuse conditions with a library and editor. Build rules from attributes like authentication and Active Directory to enforce policies.
Explore how Cisco identity services engine enables device administration and secure network access by authenticating users and endpoints, enforcing policy-based command privileges, and assigning VLANs and ACLs.
Master the triple a: authentication, authorization, and accounting for network and device access. See how Cisco ISE enforces policies, uses radius or tacacs, and records usage for audits.
Compare tacacs+ and radius protocols in Cisco ISE: tacacs+ encrypts the entire packet for device administration and per-command authorization, while radius handles network access using UDP ports 1645/1646 and 1812/1813.
Explore configuring Cisco ISE 2.7 for firewall device administration, including enabling device admin services, creating groups, Active Directory integration, command sets, profiles, and admin versus read-only access via TACACS.
Master Cisco Identity Services Engine (ISE) through practical, hands-on labs and learn how to deploy, configure, secure, and troubleshoot enterprise Network Access Control (NAC) environments.
This comprehensive course is designed for network engineers, security professionals, system administrators, and Cisco certification candidates who want to develop real-world Cisco ISE deployment and administration skills. Starting from the fundamentals, you'll progress to advanced enterprise implementations using step-by-step demonstrations and production-style lab scenarios.
Cisco Identity Services Engine (ISE) is Cisco's flagship Network Access Control (NAC) and Identity Management platform. It enables organizations to enforce Zero Trust security by authenticating users and devices, applying dynamic access policies, and providing secure access across wired, wireless, and VPN networks.
Throughout this course, you will learn not only how to configure Cisco ISE, but also why each feature is important, how it integrates with enterprise infrastructure, and how to troubleshoot common deployment challenges.
What You'll Learn
Understand Cisco ISE architecture and deployment models
Install and perform the initial setup of Cisco ISE
Configure standalone and distributed deployments
Understand Cisco ISE personas and node roles
Integrate Cisco ISE with Microsoft Active Directory and LDAP
Configure Identity Sources and Identity Groups
Build Authentication and Authorization Policies
Configure Policy Sets and Conditional Access
Deploy IEEE 802.1X authentication
Configure Wired Network Access Control
Secure Wireless Networks using Cisco ISE
Configure VPN authentication and authorization
Implement TACACS+ Device Administration
Configure Guest Access Portals and Sponsor Portals
Deploy Bring Your Own Device (BYOD) onboarding
Configure Endpoint Profiling
Implement Posture Assessment and Compliance Validation
Configure Dynamic Authorization and Change of Authorization (CoA)
Implement Downloadable ACLs (dACLs)
Configure Security Group Tags (SGTs) and Cisco TrustSec
Manage Certificates and Public Key Infrastructure (PKI)
Monitor authentication events and generate operational reports
Troubleshoot authentication, authorization, profiling, posture, and endpoint issues
Apply Cisco ISE best practices for enterprise deployments
This Course Includes
Complete Cisco ISE installation and deployment
Hands-on enterprise lab demonstrations
Step-by-step configuration exercises
Real-world implementation scenarios
Wired and Wireless Network Access Control
Active Directory integration
TACACS+ Device Administration
Guest Access and Self-Registration
BYOD onboarding
Endpoint Profiling
Posture Compliance
Policy Sets and Authorization Rules
Monitoring and Reporting
Troubleshooting labs
Downloadable lab files and configuration examples
Enterprise deployment best practices
Course Curriculum
Introduction to Cisco Identity Services Engine (ISE)
Cisco ISE Architecture and Components
Installation and Initial Configuration
Deployment Models and Personas
Licensing and Node Registration
Active Directory Integration
Identity Stores and Identity Groups
Authentication Policies
Authorization Policies
Policy Sets
Wired 802.1X Authentication
Wireless Authentication
VPN Authentication
Guest Access Configuration
BYOD Deployment
Endpoint Profiling
Posture Assessment
TACACS+ Device Administration
Certificates and PKI
Monitoring, Logging, and Reporting
Troubleshooting Enterprise Deployments
Why Learn Cisco ISE?
As organizations adopt Zero Trust Security, identity-based access control has become a critical component of enterprise network security. Cisco Identity Services Engine (ISE) provides centralized policy management that enables organizations to identify users and devices, verify compliance, and automatically enforce security policies across the network.
Cisco ISE helps organizations:
Secure wired, wireless, and VPN access
Enforce Zero Trust security policies
Automate network segmentation
Control user and device access
Simplify security policy management
Improve compliance and visibility
Reduce operational complexity
Protect enterprise IT and OT environments
Cisco ISE is widely deployed across enterprises, government agencies, healthcare organizations, financial institutions, universities, and service providers, making it one of the most valuable skills for modern network and security professionals.
Who This Course Is For
Network Engineers
Security Engineers
Network Administrators
System Administrators
Cisco Certification Candidates
Network Access Control (NAC) Administrators
Enterprise Infrastructure Engineers
Cybersecurity Professionals
IT Professionals responsible for identity and access management
Prerequisites
To get the most from this course, you should have:
Basic networking knowledge
Familiarity with TCP/IP addressing
Basic understanding of switching and routing
Knowledge of Cisco networking fundamentals is recommended but not required
No previous Cisco ISE experience is required. Every concept is explained from the ground up using practical demonstrations.
By the End of This Course
By completing this course, you will confidently deploy, configure, administer, monitor, and troubleshoot Cisco Identity Services Engine in enterprise environments. You will gain the practical skills needed to implement secure wired, wireless, and VPN authentication, integrate Cisco ISE with Active Directory, deploy Guest and BYOD services, enforce posture compliance, manage network devices with TACACS+, and build a modern Zero Trust Network Access solution.
Whether your goal is to advance your networking career, implement Cisco ISE in production, or prepare for Cisco enterprise security certifications, this course provides the hands-on experience and practical knowledge needed to succeed.