Overview #
To integrate with Cisco Identity Service Engine (ISE) feature, ensure the following requirements and dependencies are met.
API Access #
The following Cisco ISE API Services needs to be enabled for basic functionality such as Monitor, Create, Read, Update and Delete endpoint data in an Endpoint Identity Group.
- API Service Settings for Primary Administration Node
-
- ERS (Read/Write)
- Open API (Read/Write)
- MnT API (Read)
API Version #
ISE 3.2 Patch 2 and above (API v1)
API Access Requirements #
The following table details the necessary API access from the Netgraph API Service for the integration to function correctly. Each API endpoint is listed with the corresponding HTTP operations and the reasons for access.
Integration is based on API communication between the API Service and Cisco ISE API Gateway.
| ERS API | Reason |
| /ers/config/endpoint* | Search and Create Endpoints |
| /ers/config/endpoint/** | Update and Delete Endpoints |
| /ers/config/endpointgroup* | To display, connect and verify ISE Endpoint Identity Groups |
| Open API | Reason |
| /api/v1/endpoint* | Search and Create Endpoints |
| /api/v1/endpoint/** | Update and Delete Endpoints |
| /api/v1/endpoint-custom-attribute* | Search and Create Endpoints Custom Attributes |
| /api/v1/endpoint-custom-attribute/** | Update and Delete Endpoints Custom Attributes |
| MnT API | Reason |
| /admin/API/mnt/** | Retrieve Endpoint session data |
API User #
An ISE user with proper access permissions. MnT Admin, ERS Admin and Open API privileges are necessary.
Endpoint Custom Attributes #
The following Endpoint Custom Attributes are required in Cisco ISE.
| Endpoint Custom Attributes | Type |
| ngCreatedBy | String |
| ngCreatedAt | String |
| ngUpdatedBy | String |
| ngUpdatedAt | String |
| ngDeviceType | String |
| ngPSK | String |
Connection Point (CP) #
To integrate with the Netgraph Connectivity Platform – ISE Device Management, the specified ISE APIs of the local ISE infrastructure need to be able to connect to the service Connection Point(s).
Netgraph Connection Point when integrating by using ISE Device Management is:
- Netgraph Connectivity Platform, ISE Device Mgmt API Service.
Note! The Netgraph ISE Device Mgmt API Service host URLs are listed in the NCP Administration portal and depend on SaaS delivery option.