Configuring a pxGrid Cloud identity source

Before you begin, create a Cisco Account.

Important

This topic applies to Cisco ISE version 3.4 or later. If you are using an earlier version, see Configuring a pxGrid Cloud identity source (Cisco ISE 3.3 or earlier) instead.

Summary

The key components involved in configuring a pxGrid Cloud identity source are:

  • Cisco ISE: Enables pxGrid Cloud service and creates the connection

  • Catalyst Cloud Portal: Creates and manages app instances for authentication

  • Cloud-Delivered Firewall Management Center: Receives user data and creates identity sources for policy enforcement

Workflow

Configure a pxGrid Cloud identity source
The configuration process for a network device is illustrated, highlighting key settings and options available in the interface.Enable the pxGrid Cloud service in Cisco ISERegister the pxGrid Cloud connection with Cisco ISECreate an app instanceCreate an app instanceCreate a pxGrid Cloud identity sourceActivate the app instanceActivate the pxGrid Cloud identity source

These are the stages of configuring a pxGrid Cloud identity source using Cisco ISE, the Catalyst Cloud Portal, and Cloud-Delivered Firewall Management Center:

  1. Enable pxGrid Cloud in Cisco ISE. pxGrid Cloud enables you to subscribe to offers and to register apps (in this case, the Cloud-Delivered Firewall Management Center) for secure data exchange in a cloud environment. For more information, see Enable the pxGrid Cloud service in Cisco ISE.
  2. Create an app instance and get the one-time password (OTP) required to create the pxGrid Cloud identity source in the Catalyst Cloud Portal. For more information, see Create an app instance.
  3. Create the pxGrid Cloud identity source in the Cloud-Delivered Firewall Management Center. The identity source enables the Cloud-Delivered Firewall Management Center to authenticate with Cisco ISE and the Catalyst Cloud Portal so it can receive user data from Cisco ISE. For more information, see Create the identity source.
  4. Activate the app instance in the Catalyst Cloud Portal. For more information, see Activate the app instance.
  5. Activate the pxGrid Cloud identity source in the Cloud-Delivered Firewall Management Center. For more information, see Activate the pxGrid Cloud identity source.

What’s next

After you complete this configuration process, you can:

  • Test the pxGrid Cloud identity source to make sure it's working properly. For more information, see Test the pxGrid Cloud identity source.

  • Create dynamic attributes filters, which define what dynamic objects are sent to the Cloud-Delivered Firewall Management Center. For more information, see Create dynamic attributes filters.

  • Use the pxGrid Cloud identity source to enable dynamic objects, Microsoft AD user and groups, and Azure AD users and groups in access control rules.