Globalprotect with Cisco ISE

cancel
Showing results for 
Search instead for 
Did you mean: 

Globalprotect with Cisco ISE

L2 Linker

we are using PA Globalprotect for Remote VPN users. Currently planning to implement Cisco ISE posture for RVPN clients. 

how can I integrate Globalprotect with Cisco ISE posture module.

4 REPLIES 4

L4 Transporter

Thank you @charles07 for posting question.

 

The ultimate answer is no. The Cisco ISE posture module will only work with Cisco AnyConnect client. Unfortunately there is no integration support for 3d party vpn clients. This information is backed by my Cisco SE. You can still use ISE for authentication of Global Protect clients. If posture check by ISE is a must, then you will unfortunately have to go with AnyConnect.

 

Kind Regards

Pavel

Pavel Kucera

L4 Transporter

Hi @charles07 ,

 

Have you considered using HIP-Based Policy Enforcement?  This is the PANW equivalent of ISE posture.  This feature is integrated with your existing GlobalProtect (GP) clients.  However, it does require a GP license.  GP is easy to integrate with ISE as a RADIUS server.  The easiest solution would be to let the firewall determine HIP compliance and access, but that possibly could be accomplished with ISE using VSAs.

 

https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/host-information/configure-h...

 

Regards,

Tom

Help the community: Like helpful comments and mark solutions.

Hi @TomYoung GP HIP profile is not equivalent to ISE posture. Much features with ISE are missing in GP HIP.

L4 Transporter

That statement is not supported by facts.  (I'm not saying you don't have any.  You didn't state any.) A HIP object can be configured to check mobile device info/settings/apps, PC patch info, personal firewalls, anti-malware/virus software, disk backup, disk encryption, DLP software, certificates, process checks, registry entries, etc.  What specific features does ISE Posture check that are not included?  I am interested in knowing.  I would like to keep this forum technical.

Help the community: Like helpful comments and mark solutions.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!