Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Cisco Identity Services Engine (ISE) 2.7 Training Part-1/2
Rating: 4.5 out of 5(1,522 ratings)
9,127 students

Cisco Identity Services Engine (ISE) 2.7 Training Part-1/2

Learn Cisco Identity Services Engine (ISE) 2.7 with Step by Step Lab Workbook
Created byAhmad Ali
Last updated 3/2025
English
English [Auto],Spanish [Auto],

What you'll learn

  • Introduction to Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine (ISE) CLI Commands.
  • Cisco Identity Services Engine Basic Terminologies.
  • Cisco Identity Services Engine Four Persona Theory.
  • Cisco Identity Services Engine Deployment Options.
  • Introduction to Device Administration & Network Access.
  • Introduction, Theory and Concept of AAA Server.
  • Introduction and Concept of 802.1X (Dot1x) & Components.
  • Introduction to Media Access Control Authentication Bypass.
  • Introduction and Concept of Downloadable ACL (DACL).
  • Introduction and Concept of Dynamic VLAN (DVLAN).
  • Introduction to Certificate Management in Cisco ISE.
  • Configure and Verify ISE Integration with Microsoft AD.
  • Introduction to Identity Services Engine Deployment Models.
  • Introduction, Configure & Verify FTP Repository in Cisco ISE.
  • Introduction to Backup & Restore and Types of Backup in ISE.
  • Introduction to Cisco ISE Administration and Admin Access.
  • Introduction & Theory of EasyConnect Passive ID in Cisco ISE.

Course content

1 section64 lectures18h 57m total length
  • Lecture-01:Introduction to Cisco Identity Services Engine (ISE).17:40

    Introduces Cisco ISE as a centralized security policy platform that provides identity and context, enabling AAA, posture, profile, guest access, BYOD, and dynamic VLAN-based segmentation with pxGrid integration.

  • Lecture-02:Understanding Cisco Identity Services Engine Use Cases.12:05

    Explore Cisco ISE 2.7 use cases for secure guest access, isolated wired and wireless networks, and posture-driven access. See asset visibility, profiling, BYOD support, and dynamic segmentation enabling policy enforcement.

  • Lecture-03:Install and Configure Cisco ISE on VMware Workstation.11:44

    Learn to install Cisco ISE 2.7 on VMware Workstation using the ova file, with a 90-day evaluation license and guided initial setup.

  • Lecture-04:Install and Configure Cisco ISE on EVE-NG Simulation.12:46

    Learn to install Cisco ISE on Eve-NG or GNS3, configure storage and images, copy files, and perform the initial CLI setup for ISE.

  • Lecture-05:Install and Configure Cisco ISE on VMware ESXI Server.5:56

    Learn how to install Cisco ISE 2.7 on VMware ESXi using an OVA file, configure storage, network, evaluation deployment, and complete setup with hostname, IP, DNS, and SSH.

  • Lecture-06:Cisco Identity Services Engine (ISE) CLI Commands.26:00

    Explore Cisco ISE CLI basics, exec and configuration modes, essential show and management commands, and practical tips for ssh access, password resets, and application status.

  • Lecture-07:Configure Cisco Identity Services Engine ISE Topology.21:04

    Configure a two-node Cisco ISE topology with primary and secondary ISE, switches, and a Windows Server 2012 for FTP, DNS, DHCP, NTP, and certificate services.

  • Lecture-08:Install and Configure Active Directory & Create Users.22:56

    Install and configure Active Directory on a Windows server, promote it to a domain controller for test.local, and create an organizational unit structure with example users and groups.

  • Lecture-09:Install and Configure Domain Name System & Create hosts.6:02

    Configure a DNS server for active directory by creating forward and reverse lookup zones, add host records for ise1 and ise2, and verify resolution with nslookup.

  • Lecture-10:Install and Configure DHCP Server and Create Four Scopes.9:23

    Install and configure a dhcp server on Windows Server, activate dhcp, and create four scopes for vlan 10, 20, 30, and 40 with 192.168.x.x addresses, gateway, and dns settings.

  • Lecture-11:Install, Configure and Verify Network Time Protocol NTP.6:58

    Configure Windows Server 2012 as an ntp server using group policy editor and time services, enable ntp, set the announce flag to 5, and verify with ntp tool or ndp.

  • Lecture-12:Install, Configure & Verify Certificate Authority Server.11:58

    Install, configure, and verify a certificate authority server using Active Directory Certificate Services, including enterprise and root CAs, sha-256 keys, web enrollment, and testing with Cisco ISE lab scenarios.

  • Lecture-13:Install, Configure & Verify File Transfer Protocol Server.8:00

    Learn to set up an FTP server for backup and restore of Cisco ISE pages, configuring FTP in IIS, and testing with a test file.

  • Lecture-14:Configure, Test, and Verify Cisco Switches (SW1 and SW2).22:39

    Configure switch one and switch two with vlans ten, twenty, thirty, forty, and hundred, set up trunking, and enable ip routing to test and verify vlan connectivity.

  • Lecture-15:Configure, Test and Verify Edge Router and DNS Forwarder.22:47

    Configure, test, and verify an edge router to enable internet access by setting up interfaces, dns, nat inside/outside, aclS, and a default route, then validate connectivity and name resolution.

  • Lecture-16:Configure two Cisco Identity Services Engine (ISE) Nodes.11:12

    Configure two ISE nodes by running setup, setting hostnames eyes one and eyes two, IPs, DNS, and time zone, enabling SSH, and verifying connectivity by pinging gateway and name server.

  • Lecture-17:Configure and Verify Cisco Wireless LAN Controller (WLC).6:24

    Configure and verify a virtual wireless LAN controller (wlc) by setting system name, admin credentials, management and dhcp interfaces, mobility, ssid, and web access, then enable http/https and verify connectivity.

  • Lecture-18:Cisco Identity Services Engine(ISE) Dashboard Walk-Through.24:21

    Learn how the Cisco ISE 2.7 dashboard presents dashlets for system summary, endpoints, and network devices, and how to customize layouts and navigate policy and administration.

  • Lecture-19:Cisco Identity Services Engine(ISE) Basic Terminologies.28:05

    Explore Cisco ISE basics: defining identity and identity stores, internal and external identities, local endpoints, and how nodes, personas, and services enable authentication, authorization, and policy management.

  • Lecture-20:Cisco Identity Services Engine(ISE) Four Personas Theory.15:08

    Cisco ISE defines four personas—policy service node, administration node, monitoring node, and pxGrid controller—each delivering distinct services; admin and monitoring can be primary/secondary, PSN runs actively.

  • Lecture-21:Cisco Identity Services Engine(ISE) Old and New Licenses.34:19

    Explore Cisco ISE licensing, comparing traditional and smart licenses, base plus device administration and VM licenses, and how standalone and distributed deployments affect licensing in ISE 2.7.

  • Lecture-22:Introduction to Certificate Management in Cisco ISE.28:42

    Learn how certificates prove identity and secure Cisco ISE communications, covering admin, EAP, portal, pxgrid, and radius dtls certificates, as well as wildcard, system, and trusted CA concepts.

  • Lecture-23:Cisco Identity Services Engine Certificate Configuration.29:57

    Guide certificate enrollment for Cisco ISE, configure a CA, import trusted certificates, generate a multi-use certificate for ISE nodes, and validate browser trust after system restart.

  • Lecture-24:Introduction to ISE Integration with Active Directory.7:12

    Learn how to integrate Cisco ISE with Active Directory to enable user and machine authentication, and verify essential prerequisites like domain credentials, admin privileges, time sync, and DNS connectivity.

  • Lecture-25:Configure and Verify ISE Integration with Microsoft AD.12:16

    Configure and verify Cisco ISE 2.7 integration with Microsoft Active Directory by joining AD, retrieving groups, and defining an identity source sequence on ISE 1 and ISE 2.

  • Lecture-26:Introduction to Identity Services Engine Deployment Models.24:27

    Explore Cisco ISE deployment models from standalone single-box labs to scalable distributed deployments in small, medium, and large networks, detailing PAN, MMT, PSN, and pxGrid roles.

  • Lecture-27:Configure and Verify Cisco ISE High availability Deployment.30:29

    Learn to configure Cisco ISE high availability deployment by promoting ISE-1 to primary, joining ISE-2 as secondary, and validating prerequisites such as same version, DNS, hostnames, and trusted certificates.

  • Lecture-28:Introduction, Configure & Verify FTP Repository in Cisco ISE.14:38

    Configure and verify an FTP repository in Cisco ISE using GUI for persistence across all deployment nodes, or CLI for local, temporary repositories, with validation and testing.

  • Lecture-29:Install & Verify Patches in Cisco Identity Services Engine.24:24

    Learn to locate, download, verify MD5 checksums, and install the latest Cisco ISE patches in standalone and distributed deployments, then verify with show version and patch management tools.

  • Lecture-30:Introduction to Backup & Restore and Types of Backup in ISE.10:34

    Perform on-demand and scheduled backups of Cisco ISE. Learn to restore backups across primary, high availability, and standalone deployments using CLI or GUI, with certificate authority considerations.

  • Lecture-31:Configure and Verify two Types of Backup in Cisco ISE Lab.14:39

    Configure and verify configuration data backup and operational data backup in Cisco ISE using GUI, FTP repository, and encryption keys, then schedule automated backups and verify via CLI.

  • Lecture-32:Configure and Verify Restore the Backup in Cisco ISE Lab.2:38

    Learn to restore a Cisco ISE backup by selecting the configuration backup, confirming with the restore key, and verifying progress with show restore status as the system reboots.

  • Lecture-33:Export and Import Cisco ISE Certificates Through GUI & CLI.15:09

    Export and import certificates for Cisco ISE using GUI and CLI. Back up certificates and private keys separately from configuration using the ISE CLI.

  • Lecture-34:Upgrade Cisco ISE Version 2.7 to Cisco ISE new Version 3.18:11

    Upgrade Cisco ISE from 2.7 to version 3 by applying latest patches, downloading the upgrade bundle, verifying hashes, and performing a split upgrade on a standalone device.

  • Lecture-35:Introduction to Cisco ISE Administration and Admin Access.28:15

    Learn how to configure Cisco ISE admin access with internal authentication, robust password and account policies, and RBAC-based menu and data access controls for admin groups.

  • Lecture-36:Integrate Active Directory Groups for ISE Administration.18:09

    Log in to Cisco ISE using Active Directory groups, map those groups to RBAC policies, and enable centralized administration with admin and read-only access.

  • Lecture-37:Join Microsoft Windows 10 to Active Directory (AD) Domain.10:46

    Join a Windows 10 PC to the Active Directory domain test.local by changing the computer name, entering the domain, and rebooting; verify login with domain users.

  • Lecture-38:Introduction and Theory of IEEE 802.1X (Dot1x) Wired in ISE.23:24

    Explain how IEEE 802.1X wired authentication uses EAP over LAN to secure port-based access in wired networks, with supplicant, authenticator, and authentication server, and radius-based authentication via Cisco ISE.

  • Lecture-39:Introduction and Theory of IEEE 802.1X (Dot1x) Components.9:10

    Identify the dot1x components—supplicant, authenticator, and authentication server—and describe how end devices like PCs or tablets are authenticated via a switch, Radius/ISE, and an Active Directory identity source.

  • Lecture-40:Introduction and Theory of IEEE 802.1X (Dot1x) Port States.20:00

    Explore 802.1x port states auto, force authorized, and force unauthorized, and learn how authentication via eapol governs port authorization on switches.

  • Lecture-41:Introduction and Theory of IEEE 802.1X (Dot1x) two Phasing.30:16
  • Lecture-42:Introduction and Theory of IEEE 802.1X (Dot1x) Four Modes.33:26

    Explore 802.1X operating modes: single host, multi host, multi domain, and multi authentication, showing how authentication on a port with MAC addresses and access control shapes network access.

  • Lecture-43:Configure and Verify Cisco ISE IEEE 802.1X (Dot1x) Wired Lab.43:39

    Configure and verify Cisco ISE 2.7 IEEE 802.1X wired lab by deploying radius servers, policy sets, and domain/non-domain client authentication on switch ports.

  • Lecture-44:Introduction and Theory of Downloadable Access List (DACL).6:36

    Discover how downloadable ACLs from Cisco ISE automatically download to access layer switches, providing a single-point policy to dynamically restrict user access after authentication.

  • Lecture-45:Configure and Verify Downloadable Access List (DACL) Lab.39:50

    Demonstrates configuring and verifying downloadable ACLs with Cisco ISE 2.7 to restrict contractor access while allowing employees broad access, using dot1x, policy sets, and authorization profiles.

  • Lecture-46:Introduction of Dynamic Virtual Local Area Networks (VLAN).5:03

    Explore dynamic VLANs in Cisco ISE 2.7, and see how authentication-based policies automatically assign endpoints to specific VLANs, replacing static port configurations for both wired and wireless access.

  • Lecture-47:Configure & Verify Dynamic Virtual Local Area Networks Lab.16:03

    Configure and verify dynamic VLAN assignment with Cisco ISE 2.7, mapping employee and contractor users to VLAN 10 and VLAN 20 via decals and authorization policies, and validate through testing.

  • Lecture-48:Introduction to Certificate-Based Authentication User & PC Lab.7:12

    Explore certificate-based authentication for user and machine on PC one, using user and computer templates, group policies, dot1x, and ISE policy sets with Active Directory and certificate services.

  • Lecture-49:Create User and Computer Certificate Templates in CA Server.7:42

    Create two certificate templates in the certificate authority for user and workstation authentication, duplicating templates, configuring security and subject name, enabling auto enrollment, and issuing them.

  • Lecture-50:Create User and Computer Group Policy in Windows Server Lab.3:09

    Enable certificate services client auto enrollment for computer and user configurations by editing the default domain policy and enabling auto enrollment under the public key policy.

  • Lecture-51:Create IEEE 802.1X (Dot1x) Client Group Policy in Win Server.4:46

    Create an IEEE 802.1X client group policy on Windows Server to enable certificate-based authentication using smartcard and other certificates, configuring user and computer authentication.

  • Lecture-52:Configure and Verify Certificate Based Authentication Lab.29:07

    This lab demonstrates configuring certificate based authentication with Cisco ISE 2.7, including certificate profiles, identity source sequences, EAP-TLS, downloadable ACLs, and machine and user authorization verification.

  • Lecture-53:Introduction to Media Access Control Authentication Bypass MAB.11:42

    Explore how Mab uses a device mac address as the credential, with switches dropping traffic until the first frame is learned and sent to Cisco ISE via radius.

  • Lecture-54:Configure Media Access Control Authentication Bypass MAB Lab.17:06

    Configure mab as a fallback when dot1x is unavailable, register endpoints in the internal identity store, and verify map-based access on a Cisco ISE 2.7 lab.

  • Lecture-55:Introduction & Theory of EasyConnect Passive ID in Cisco ISE.12:57

    Learn how Cisco ISE easy connect provides port-based network access without a supplicant, using passive identity and Active Directory to grant limited access initially and full access after authorization changes.

  • Lecture-56:Configure and Verify in Cisco ISE EasyConnect Passive ID Lab.29:26

    Configure and verify Cisco ISE easyconnect passive ID lab across two nodes, integrating Active Directory via WMI and deploying ACLs and policies for easyconnect, employee, and contractor.

  • Lecture-57:Introduction, Concept and Theory of Policy Sets in Cisco ISE.24:17

    Explore policy sets in Cisco ISE, including network access and device administration, and learn how authentication and authorization rules are organized under a unified policy set.

  • Lecture-58:Introduction, Concept and Theory of Authentication Policies.5:00

    Explore authentication policies in ISE, from policy sets and conditions to hits and actions, including reject, drop, and continue through radius, then proceed to authorization.

  • Lecture-59:Introduction, Concept and Theory of Authorization Policies.8:00

    Explain authorization policies that apply after authentication, detailing conditions, profiles, and security groups for network and device access; differentiate local, global, and regular exceptions and their evaluation order.

  • Lecture-60:Introduction and Theory of Conditions Studio in Policy Set.11:40

    Master condition studio in Cisco ISE 2.7 to create, save, and reuse conditions with a library and editor. Build rules from attributes like authentication and Active Directory to enforce policies.

  • Lecture-61:Introduction of Device Administration and Network Access.22:52

    Explore how Cisco identity services engine enables device administration and secure network access by authenticating users and endpoints, enforcing policy-based command privileges, and assigning VLANs and ACLs.

  • Lecture-62:Introduction of Authentication, Authorization & Accounting.22:46

    Master the triple a: authentication, authorization, and accounting for network and device access. See how Cisco ISE enforces policies, uses radius or tacacs, and records usage for audits.

  • Lecture-63:Introduction of AAA Options TACACS+ and RADIUS Protocols.31:46

    Compare tacacs+ and radius protocols in Cisco ISE: tacacs+ encrypts the entire packet for device administration and per-command authorization, while radius handles network access using UDP ports 1645/1646 and 1812/1813.

  • Lecture-64:Configure & Verify Cisco ASA Firewall Device Administration.32:45

    Explore configuring Cisco ISE 2.7 for firewall device administration, including enabling device admin services, creating groups, Active Directory integration, command sets, profiles, and admin versus read-only access via TACACS.

Requirements

  • Basic IP and security knowledge is nice to have.
  • Students needs to understand Networking Fundamentals.
  • CCNA routing and Switching Knowledge
  • Basic Knowledge of Cisco Identity Services Engine

Description

Master Cisco Identity Services Engine (ISE) through practical, hands-on labs and learn how to deploy, configure, secure, and troubleshoot enterprise Network Access Control (NAC) environments.

This comprehensive course is designed for network engineers, security professionals, system administrators, and Cisco certification candidates who want to develop real-world Cisco ISE deployment and administration skills. Starting from the fundamentals, you'll progress to advanced enterprise implementations using step-by-step demonstrations and production-style lab scenarios.

Cisco Identity Services Engine (ISE) is Cisco's flagship Network Access Control (NAC) and Identity Management platform. It enables organizations to enforce Zero Trust security by authenticating users and devices, applying dynamic access policies, and providing secure access across wired, wireless, and VPN networks.

Throughout this course, you will learn not only how to configure Cisco ISE, but also why each feature is important, how it integrates with enterprise infrastructure, and how to troubleshoot common deployment challenges.

What You'll Learn

  • Understand Cisco ISE architecture and deployment models

  • Install and perform the initial setup of Cisco ISE

  • Configure standalone and distributed deployments

  • Understand Cisco ISE personas and node roles

  • Integrate Cisco ISE with Microsoft Active Directory and LDAP

  • Configure Identity Sources and Identity Groups

  • Build Authentication and Authorization Policies

  • Configure Policy Sets and Conditional Access

  • Deploy IEEE 802.1X authentication

  • Configure Wired Network Access Control

  • Secure Wireless Networks using Cisco ISE

  • Configure VPN authentication and authorization

  • Implement TACACS+ Device Administration

  • Configure Guest Access Portals and Sponsor Portals

  • Deploy Bring Your Own Device (BYOD) onboarding

  • Configure Endpoint Profiling

  • Implement Posture Assessment and Compliance Validation

  • Configure Dynamic Authorization and Change of Authorization (CoA)

  • Implement Downloadable ACLs (dACLs)

  • Configure Security Group Tags (SGTs) and Cisco TrustSec

  • Manage Certificates and Public Key Infrastructure (PKI)

  • Monitor authentication events and generate operational reports

  • Troubleshoot authentication, authorization, profiling, posture, and endpoint issues

  • Apply Cisco ISE best practices for enterprise deployments

This Course Includes

  • Complete Cisco ISE installation and deployment

  • Hands-on enterprise lab demonstrations

  • Step-by-step configuration exercises

  • Real-world implementation scenarios

  • Wired and Wireless Network Access Control

  • Active Directory integration

  • TACACS+ Device Administration

  • Guest Access and Self-Registration

  • BYOD onboarding

  • Endpoint Profiling

  • Posture Compliance

  • Policy Sets and Authorization Rules

  • Monitoring and Reporting

  • Troubleshooting labs

  • Downloadable lab files and configuration examples

  • Enterprise deployment best practices

Course Curriculum

  • Introduction to Cisco Identity Services Engine (ISE)

  • Cisco ISE Architecture and Components

  • Installation and Initial Configuration

  • Deployment Models and Personas

  • Licensing and Node Registration

  • Active Directory Integration

  • Identity Stores and Identity Groups

  • Authentication Policies

  • Authorization Policies

  • Policy Sets

  • Wired 802.1X Authentication

  • Wireless Authentication

  • VPN Authentication

  • Guest Access Configuration

  • BYOD Deployment

  • Endpoint Profiling

  • Posture Assessment

  • TACACS+ Device Administration

  • Certificates and PKI

  • Monitoring, Logging, and Reporting

  • Troubleshooting Enterprise Deployments

Why Learn Cisco ISE?

As organizations adopt Zero Trust Security, identity-based access control has become a critical component of enterprise network security. Cisco Identity Services Engine (ISE) provides centralized policy management that enables organizations to identify users and devices, verify compliance, and automatically enforce security policies across the network.

Cisco ISE helps organizations:

  • Secure wired, wireless, and VPN access

  • Enforce Zero Trust security policies

  • Automate network segmentation

  • Control user and device access

  • Simplify security policy management

  • Improve compliance and visibility

  • Reduce operational complexity

  • Protect enterprise IT and OT environments

Cisco ISE is widely deployed across enterprises, government agencies, healthcare organizations, financial institutions, universities, and service providers, making it one of the most valuable skills for modern network and security professionals.

Who This Course Is For

  • Network Engineers

  • Security Engineers

  • Network Administrators

  • System Administrators

  • Cisco Certification Candidates

  • Network Access Control (NAC) Administrators

  • Enterprise Infrastructure Engineers

  • Cybersecurity Professionals

  • IT Professionals responsible for identity and access management

Prerequisites

To get the most from this course, you should have:

  • Basic networking knowledge

  • Familiarity with TCP/IP addressing

  • Basic understanding of switching and routing

  • Knowledge of Cisco networking fundamentals is recommended but not required

No previous Cisco ISE experience is required. Every concept is explained from the ground up using practical demonstrations.

By the End of This Course

By completing this course, you will confidently deploy, configure, administer, monitor, and troubleshoot Cisco Identity Services Engine in enterprise environments. You will gain the practical skills needed to implement secure wired, wireless, and VPN authentication, integrate Cisco ISE with Active Directory, deploy Guest and BYOD services, enforce posture compliance, manage network devices with TACACS+, and build a modern Zero Trust Network Access solution.

Whether your goal is to advance your networking career, implement Cisco ISE in production, or prepare for Cisco enterprise security certifications, this course provides the hands-on experience and practical knowledge needed to succeed.

Who this course is for:

  • Course has been designed for anyone who wants to start learning Cisco ISE
  • Any Network or Security Engineer want to learn or polish their Skills.
  • Any Network or Security Engineer want to upgrade Cisco ISE Skills