Cisco pxGrid Integration

Rapid Response Capabilities using Cisco pxGrid

Cisco pxGrid

With Cisco pxGrid (Platform Exchange Grid), your multiple security products can now share data and work together. This open, scalable, and IETF standards-driven platform helps you automate security to get answers and contain threats faster.

Please Note:

  1. The integration is for pxGrid 2.0 and compatible with Cisco ISE 2.4 and above.

  2. The below configuration works without certs for now. Support for Certs will be added soon.

Blusapphire integration with Cisco pxGrid

1. Provide contextual information in BluSapphire UI, using session information provided by Cisco ISE.

2. Provide quarantine action on an end-point using the ANC policy.

Configuration

Registration using username and password.

2. Enter the client hostname in Client Node, Enter pxGrid Nodes in the pxGrid Nodes text area and click on submit button to save the Client Name and pxGrid Nodes.

3. HA failover can be done by entering two pxGrid Nodes. BluSapphire connects with both the nodes simultaneously. Initially, the first node/primary node is considered the active node. If the primary node goes offline, the secondary node is marked as the active node. If the primary node comes back online then it will be automatically marked as the active node. Data will be processed from the current active node only to avoid deduplication.

4. Click on Register button to Initiate client registration using username/password in Cisco ISE.

5. Click on the Registration status button to view the status of registration.

7. For approving client on Cisco ISE, Login as Administrator and Open the Cisco ISE --> pxGrid page to approve the pending registration.

9. Now, select the client and click on approve.

Create ANC Policy

To create ANC Policy, Login to Cisco ISE as an administrative user and do the following activities

Scenarios

Contextual Information

BluSapphire takes contextual information feed from Cisco ISE and uses that to show any device/host’s contextual information. You can see them as shown below:

4. Now Click on Triage (Tr) link at the top right corner beside the previous and next entries.

5. The triage page opens in a new tab, as shown below. Double click on the right panel entry, to fetch the host details from session details captured from Cisco pxGrid.

6. Host details are shown in the below panels

Quarantine / Response Action

4. Now Click on Triage (Tr) link at the top right corner beside the previous and next entries.

6. Host information is shown as in below panel.

Troubleshooting

1. Contextual Information/ Host Information does not display anything.

Solution:

Please check if you completed all the Registration Steps shown in the Registration section above.

Check that the Registration Status shows "Enabled".

If the registration status shows "Pending" or "Disabled". Login to Cisco ISE console go to Cisco ISE -> pxGrid -> Web Clients and verify the client status is shown ON.

2. Quarantine does not work.

Solution: Please follow the troubleshooting steps described above. Additionally check if an ANC policy has been defined as described in "Create ANC Policy" section above.

Last updated