How to Configure a pxGrid Cloud Identity Source

Before you begin, create a Cisco DNA Portal account.

The following figure shows the steps to configure a pxGrid cloud identity source using Cisco ISE, the Cisco DNA Portal, and cloud-delivered Firewall Management Center.

Click an area in the figure to learn more about it or click one of the links following the figure.

Enable pxGrid Cloud Service in Cisco ISERegister Cisco ISE with the Cisco DNA PortalRegister the pxGrid Cloud Connection with Cisco ISECreate and Subscribe to the Firewall Management Center ApplicationCreate the Identity SourceVerify It's Working
Configure a pxGrid cloud identity source

Cisco ISE

Enable the pxGrid Cloud in Cisco ISE.

pxGrid Cloud enables you to subscribe to offers and to register apps (in this case, the cloud-delivered Firewall Management Center) for secure data exchange in a cloud environment.

For more information, see Enable pxGrid Cloud Service in Cisco ISE.

Cisco DNA Portal

Register Cisco ISE in the Cisco DNA portal and authenticate communication between Cisco ISE and the Cisco DNA Portal.

For more information, see Register Cisco ISE with the Cisco DNA Portal.

,

Cisco ISE, Cisco DNA Portal

Register the pxGrid Cloud with Cisco ISE and verify the registration.

For more information, see Register the pxGrid Cloud Connection with Cisco ISE.

,

Cisco DNA Portal, cloud-delivered Firewall Management Center

Create an application instance in the Cisco DNA Portal and get the one-time password (OTP).

The application instance enables the cloud-delivered Firewall Management Center to authenticate with Cisco ISE using the pxGrid Cloud service.

The OTP, required for the next step, expires in 60 minutes.

Cloud-delivered Firewall Management Center

Create the pxGrid cloud identity source using the OTP you got in the previous step.

Linking the app enables the cloud-delivered Firewall Management Center to authenticate with ISE and the Cisco DNA Portal so it can receive user data from Cisco ISE.

For more information, see Create the Identity Source.

Cisco DNA Portal

Reverify the application instance.

Activate the App Instance.

Cloud-delivered Firewall Management Center

Verify the identity source is active.

Verify It's Working.

After you have completed all the preceding tasks, you can:

  • Create dynamic attributes filters, which define what dynamic objects are sent to the cloud-delivered Firewall Management Center.

    For more information, see Create Dynamic Attributes Filters.

  • After you configure the pxGrid cloud identity source, you can use any of the following in access control rules:

    • Dynamic objects

    • Microsoft AD user and groups

    • Azure AD users and groups

See Enable pxGrid Cloud Service in Cisco ISE.