Cisco ISE 3.
5 release announcement
We are very excited to announce the release and availability of Cisco Identity Services
Engine (ISE) 3.5. We thank both internal and external stakeholders, customers, partners
who helped us shape this release.
Security starts with Identity. Strong identity edge needs a platform that secures identity
using granular context from users, devices and workloads to provide secure access and
end to end segmentation that cuts across network and security domain. ISE is that glue, a
foundational element to Zero Trust Access.
Cisco ISE 3.5 is significant in three broad areas based on customer challenges to provide
Identity and Security enhancements, Superior device classification and Platform
enhancements and resilience to support enterprise customers.
• Identity and Security Solutions.
Device authorization for Entra ID: Customers are transitioning to Entra ID as their Id
store and need full support with both device and user authorization to track assets
owned by the organizations and tie in with the employee. ISE is supporting user and
device authorization chaining with Entra ID in the current release
Continuous monitoring of user/device attributes in Entra ID: Government
customers in certain geographies do not prefer MFA and wanted double authentication
to tie device and users. They wanted to continuously monitor changes in user/ device
attributes in Entra ID and take action by reducing level of access. ISE supports
monitoring user or device attributes for device authentication and SAML based user
authentication in ISE.
Secure API authentication mechanisms: In general, there is a growing need to
support more secure authentication mechanisms such as API keys/OAUTH 2.0 or
certificates in our API’s to get context in. Here are the changes to our API’s improve
secure authentication
• Our Threat Centric NAC API for Tenable will use more secure authentication
mechanisms (API keys and Cert authentication) to get upto 20 attributes that
can be used to differentiate access to the endpoint.
• Our pxGrid-direct that synchronizes with configuration management databases
to get bulk updates getting context-in to be used in our access policy is
augmented with more secure authentication mechanism using API keys/OAUTH
2.0. This is needed to support context in from security vendors such as
Crowdstrike, Microsoft MDE etc.
-
Common policy and Cross Domain context sharing: A big pain point for large
customers is managing policies for users/endpoints access to application workloads
since the access patterns are varied. This is a challenge for organizations to implement
Zero Trust. This needs better management of policies in all key domain/policy control
points that acts as an entry point for users/devices access applications. Organizations
are siloed that makes them hard to create and maintain consistent policies across all
policy controllers across network and security domain.
• Cisco ISE innovation using common policy framework is laying a foundation for
organization towards the goal of creating consistent policies across multiple
policy controllers by learning and sharing user/device and workload context with
network, security policy controllers
• We are extending this to new integrations by sharing specific context (e.g: SGT’s)
to Cisco SASE and network security platforms such as Cisco Secure Access and
Cloud delivered firewall management system(cd-FMC) to create native policies
that will help customers create consistent policies across their security eco-
system.
Cisco ISE already supports integration with Cisco Catalyst center, Meraki and
SDWAN on the networking side and integration with Cisco Secure Firewall,
Secure Network Analytics and Cisco Secure Workload, apart from 70+
integration with 3rd party vendors.
• We are also improving the usability and performance of policy builders such as
TrustSec policy matrix to help admins scale the number of policies to 10k SGT
and make the UI rendering seamless.
• Profiling (Device classification)
This is another major area where there are several improvements.
1. Customers were concerned about insufficient profiling and needed help with
reducing unknown endpoints in their network. Profiling certain unknown endpoints
needed manual intervention using custom profiles. ISE Admins customize profiles
to suite enterprise needs and found ISE user interface complicated and
cumbersome to use.
2. Some customers need a simple way to get information about network infrastructure
devices or assets(printers) that are company owned in a secure way. There is a need
to make profiling more deterministic, to use device information from more
authoritative sources such as posture/MDM to label endpoints.
3. Finally, after analysis Engineering team found that customers have not turned on
enough data collection methods (for e.g.: Device Sensors) to improve profiling and it
is a catch 22 situation where we need more data for better profiling but there is an
insufficient data since these probes are not turned on.
-
Here are the following features that benefits our customers by reducing the pain points,
improving user experience and overall improve profiling efficacy significantly
• New and precise device profiling: Cloud Multi-Factor classification (MFC) profiler
is a cloud enabled profiler that has thousands of fingerprints and rules to profile and
classify endpoints with multiple labels automatically with high degree of efficacy. In
our internal evaluation with a close competition, we are on par or even excelling in
certain categories. Between our legacy and the cloud profiler there is a big markup (
a 20-point or more increase) in % of endpoints labelled with the right “Endpoint
type” and others.
• Broaden profiling using simple tools: To identify infrastructure and company
assets(e.g: Printers etc) ISE now has a way to trigger and schedule endpoint SNMP
scan with SNMPv3 to identify enterprise IOT devices that can be automatically
classified using Cloud MFC-Profiler or can be customized using new simplified
custom profiles.
• Simplified custom profile: ISE 3.5 simplified the task of creating custom profiles
using structured policy interfaces to assigning Multi-Factor Classification labels
(Endpoint type, Manufacturer, Model and OS).
• Deterministic device labels: ISE 3.5 helps admin map attributes from authoritative
endpoint sources such as ISE Posture/MDM services to update MFC labels
(Endpoint type, Manufacturer, Model and Operating System).
• Tools to assess and improve data collection: Many customers did not turn on
enough profiling probes that resulted in insufficient profiling. To solve that, in
Cisco ISE 3.5 provides a way to identify lack of configuration in profiling
discovery protocols by tracking and monitoring probes in a nice graphical
dashboard view across ISE nodes (PSNs) and Network devices.
• Platform enhancements
Cisco realizes the need to make ISE platform robust and have invested improve
resilience, security and making the platform available across different customers.
• Red Hat OpenShift Platform Support
• IPv6 support for Single Stack and extended support for IPv6 for a host of ISE
features including ISE admin portal, common services, key Id stores, node
communications, API, key profiling probes, posture, TrustSec over HTTPs, pxGrid,
endpoint custom attributes.
• Stronger security with TLS 1.3: Supporting TLS 1.3 in different areas to uplift the
overall security of ISE, including Admin UI access, secure 802.1x authentications,
TACACS+, APIs, Syslogs (TCP), Guest portals, pxGrid, posture feed, Integration with
Catalyst center/Meraki and DUO.
• ISE resilience is a set of areas Engineering has analyzed with TAC/escalation that
will help reduce problems in customer deployment and to make ISE more robust
from failures.
-
o Manage slow to respond Active Directory
o Optimizing ISE resources for chatty network devices using TACACS.
o Reliable syslog’s for external servers by streamlining syslog queue.
o Relieve tied resources by correcting debug configuration back to normal.
o Monitor and reduce impact on ISE due to high traffic from profiling probes.
• ISE install and upgrade improvements: Reduce ISE install time by up to 20mins.
Upgrade to new ISE version with or without patch in the previous release.
• Licensing: We have streamlined license consumption and provided views and
reports to look at consumption across license tiers. License enforcement is relaxed
in ISE 3.5.
Download ISE 3.5 now!
ISE 3.5 Resources:
• Cisco ISE Release Notes, Release 3.5
• Cisco ISE Administrator Guide, Release 3.5
• Cisco Identity Services Engine Installation Guide, Release 3.5
• Cisco Identity Services Engine Upgrade Journey, Release 3.5
• Cisco Identity Services Engine CLI Reference Guide, Release 3.5
• Cisco Identity Services Engine API Reference Guide
• Cisco Identity Services Engine Network Component Compatibility, Release 3.5
• Network Access Control Capabilities of Network Devices with Cisco Identity Services
Engine
• Deploy Cisco Identity Services Engine Natively on Cloud Platforms(Release-
agnostic doc)
• Cisco Secure Network Server 3800 Series Appliance Hardware Installation Guide
• Sponsor Portal User Guide for Cisco Identity Services Engine
Sincerely,
Krishnan Thiruvengadam and PM team
Cisco Identity Services