Configure PASSIVE ID in ISE using Agent
This video tutorial by Diva from Zot explains configuring passive ID using an agent as a provider to map user and IP data via Active Directory, specifically using I version 3.3 and Windows Active Directory 2022.
MAIN POINTS FROM TRANSCRIPT
- Ensure compatibility between I version and Active Directory version for passive ID configuration.
- Update Microsoft .NET Framework to at least version 4.0 on the agent machine.
- Install the agent on a member server or domain controller and configure it to monitor domain controllers.
- Verify the passive identity service is enabled and the Active Directory join point is operational.
TAKEAWAYS
- Reverse DNS lookup must be configured for relevant DNS servers.
- The I server must reach the domain controller over AD agent TCP 9095.
- Use the msrpc protocol for agent configuration and provide necessary credentials.
- Verify the agent's status through the dashboard after configuration.