This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Can NCM backup / manage Cisco ISE?

I'd love to track configuration changes in Cisco ISE with NCM.  Is this possible?

  • Will SolarWinds be working on any integrations with Cisco ISE? Since ACS is going away, seems like more people will be migrating to ISE.

  • I'm unaware of any place where SW is working on ISE integration.  But you're asking in the right forum--just post the general question to SW via Thwack and you may have better luck than I.

  • What about the new Binary Configs feature?  Since ISE devices can be set to backup via FTP, couldn't we just setup the Binary Config feature to pull them this way?  I don't know a lot about ISE devices, so maybe this wouldn't work...

  • I'm looking for a way for NCM to actually request, download, store, compare, and restore ISE configurations in ways similar to that used to manage Cisco switches & routers.

    I already have ISE automatically backing up it's configuration to a remote SCP server, but it's not the same as having NCM doing the work, performing the config change reports, running Compliance checks on the configs, etc.

    No, I'm looking for the full NCM experience when it comes to managing any of my devices.  I really like what NCM is doing, what it can do, and where it's going in the future.  Anything less for backing up ISE is just a kluge that must be improved.

  • You mean like to have a script that SSH into ISE, captures a sh running-config and sh startup-config and update in NCM?

  • That's a good start.  And the files need to be transferred securely, and stored in a format that NCM can compare current and prior configs.  It's simple:  anything NCM can do with a Cisco switch, I'd like it to do with ISE configurations.

  • For the moment, what I am considering:

    I have two ISE nodes running. I have scheduled the Configuration and Opperational backups to be performed to the local ISE Server disks.

    From that point on I can fetch all the configuration files directly from the servers local drive.

    All files are accessible (run and startuo-config as well as the application configuration files).

    Not sure if that is exactly what you are looking for but for me it works, until I can find an easier way

  • I think you might be confusing my need with what's traditional and possible.

    I'm looking for a way to have NCM backup the ISE server's configuration, not the switch's configs after ISE has been applied.

    Automatic download of the ISE appliance's configurations, and then performing scheduled configuration change reports of that configuration, is my goal.

    I do already get the switches' running & startup config changes in reports.  It's the ISE servers' configs & changes that I seek.

  • So you are looking for just the backup script but you actually want ISE integrated into NCM like any other cisco switch or router.  I noticed when I was poking around that I can get the running config but that does not gather the policies etc.  You would like to see the whole ball of wax rolled into NCM.  Am I in the ball park?

  • I'd like ISE treated just like a Cisco switch or router by NCM.  Although it's an application, it would be nice to track changes to its configuration.

    I don't see it ever happening, but it would be nice . . .