LABSEC-1673 - Profiling on Solid ISE: Avoiding Network Security Pitfalls
Proctors | Andrea Bertorello None |
Security access control and network visibility have long been challenging, often involving guesswork due to the many unidentified endpoints connecting to your network. This is especially true when a variety of devices are managed by different groups or not directly provisioned by your IT department. Cisco ISE, with its advanced profiling capabilities, minimizes the guesswork by accurately identifying endpoints, categorizing them into known groups, and simplifying the creation and enforcement of security policies. In this hands-on lab, you will explore some of ISE's top capabilities, including Wi-Fi Device Analytics Data, Cisco's AI-ML-driven Rule Proposals for Endpoint Profiling, and Multi-Factor Classification for enhanced endpoint visibility. These features empower you to create nuanced authorization policies using specific attributes from connecting devices. The Multi-Factor Classification profiler leverages multiple profiling probes to gather critical endpoint attributes. Cisco ISE also provides continuous profiling suggestions based on real-time network learning, helping to reduce the number of unknown or unprofiled endpoints in your environment. With integrated device analytics from Cisco Wireless LAN Controllers, you can easily create profiling, authorization, and authentication policies for devices from key manufacturers like Apple, Intel, and Samsung, further enhancing your network security and management. For a more customized approach, this session will also explore how you can leverage open-source packet analyzers to inspect network traffic, providing additional context for identifying and profiling endpoints.