{"id":95330,"date":"2020-09-28T07:42:51","date_gmt":"2020-09-28T05:42:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2"},"modified":"2020-09-28T07:42:51","modified_gmt":"2020-09-28T05:42:51","slug":"cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2","title":{"rendered":"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/b1c271d9da09b338a0b9d8f1e5217d24.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Welcome to the second publication of the series of articles dedicated to Cisco ISE. In the first one, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/519616\/\"><u>article<\/u><\/a><\/noindex>&nbsp; we discussed the advantages and differences of Network Access Control (NAC) solutions from standard AAA, the uniqueness of Cisco ISE, its architecture, and the installation process of the product.<\/p>\n<p>In this article, we will delve into creating user accounts, adding LDAP servers, and integrating with Microsoft Active Directory, as well as the nuances of working with PassiveID. Before reading, I highly recommend familiarizing yourself with the <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/519616\/\"><u>first part<\/u><\/a><\/noindex>.<\/p>\n<h2>1. Some Terminology<\/h2>\n<p><strong>User Identity<\/strong> \u2014 a user account that contains user information and forms credentials for accessing the network. The following parameters are typically specified in User Identity: username, email address, password, account description, user group, and role.<\/p>\n<p><strong>User Groups <\/strong>\u2014 user groups \u2014 a collection of individual users that share a common set of privileges, allowing them to access a certain set of services and features in Cisco ISE.<\/p>\n<p><strong>User Identity Groups \u2014 <\/strong>are predefined user groups that already contain specific information and roles. The following User Identity Groups exist by default, and users and groups can be added to them: Employee, SponsorAllAccount, SponsorGroupAccounts, SponsorOwnAccounts (sponsor accounts for managing the guest portal), Guest, ActivatedGuest.<\/p>\n<p><strong>User Role \u2014 <\/strong>a user role \u2014 a set of permissions that defines what tasks a user can perform and which services they can access. Often, a user role is associated with a user group.<\/p>\n<p>Moreover, each user and user group has additional attributes that allow for distinction and more specific identification of that user (user group). More information can be found in <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/ise\/2-0\/admin_guide\/b_ise_admin_guide_20\/m_ise_man_stores.html#ID1089\"><u>guide<\/u><\/a><\/noindex>.<\/p>\n<h2>2. Creating Local Users<\/h2>\n<p>1) In Cisco ISE, you can create local users and use them in access policies or even assign them an administrative role for the product. Select <em>Administration \u2192 Identity Management \u2192 Identities \u2192 Users \u2192 Add.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/5e56ad32ab7c5b1b37733d8887991d5d.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 1. Adding a Local User in Cisco ISE<\/p>\n<p>2) In the window that appears, create a local user, set a password, and other understandable parameters.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/612bbc88b7f5a5f029cbd224241c15ad.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 2. Creating a Local User in Cisco ISE<\/p>\n<p>3) Users can also be imported. In this same tab <em>Administration \u2192 Identity Management \u2192 Identities \u2192 Users <\/em>select the option <em>Import <\/em>and upload a csv or txt file with the users. To obtain a template, select <em>Generate a Template<\/em>, then fill it with user information in the appropriate format.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/1fd2c0dae86103b638dc1d44bc6896a0.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 3. Importing Users into Cisco ISE<\/p>\n<h2>3. Adding LDAP Servers<\/h2>\n<p>Let me remind you that LDAP \u2014 a popular application layer protocol that allows retrieving information, authenticating, and searching for accounts in LDAP directory servers, operates over port 389 or 636 (SSL). Prominent examples of LDAP servers include Active Directory, Sun Directory, Novell eDirectory, and OpenLDAP. Each entry in the LDAP directory is defined by a DN (Distinguished Name), and the task of access policy formation involves retrieving user accounts, user groups, and attributes.<\/p>\n<p>In Cisco ISE, it is possible to configure access to multiple LDAP servers, thereby implementing redundancy. If the primary LDAP server is unavailable, ISE will attempt to connect to the secondary one, and so forth. Additionally, if there are 2 PANs, one LDAP can be prioritized for the primary PAN while another can be assigned for the secondary PAN.<\/p>\n<p>ISE supports 2 types of lookups when working with LDAP servers: User Lookup and MAC Address Lookup. User Lookup allows searching for users in the LDAP database and retrieving the following information without authentication: users and their attributes, user groups. MAC Address Lookup also allows performing a search by MAC address in LDAP directories without authentication and retrieving information about the device, groups of devices by MAC address, and other specific attributes.<\/p>\n<p>As an example of integration, we will add Active Directory to Cisco ISE as an LDAP server.<\/p>\n<p>1) Go to the tab <em>Administration \u2192 Identity Management \u2192 External Identity Sources \u2192 LDAP \u2192 Add.<\/em>&nbsp;<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/21151bf88c8a5fc9cafe2ce58418d6b9.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 4. Adding an LDAP Server<\/p>\n<p>2) In the panel <em>General <\/em>specify the name of the LDAP server and the schema (in our case, Active Directory).&nbsp;<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/93b132553a77d03bedc5b43978692c6d.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 5. Adding an LDAP Server with Active Directory Schema<\/p>\n<p>3) Next, go to the <em>Connection <\/em>tab and specify <em>Hostname\/IP address <\/em>AD servers, port (389 \u2014 LDAP, 636 \u2014 SSL LDAP), domain administrator credentials (Admin DN \u2014 full DN), other parameters can be left as default.<\/p>\n<p><em><strong>Note<\/strong><\/em>: use the admin domain data to avoid potential issues.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/dc13756a71e031c8fb1281902318d6f8.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 6. LDAP Server Data Input<\/p>\n<p>4) In the tab <em>Directory Organization <\/em>you should specify the directory scope via DN from which to pull users and user groups.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/5080b6fead47381ddb0f17bd5314fe8e.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 7. Defining directories from which to pull user groups<\/p>\n<p>5) Go to the window <em>Groups \u2192 Add \u2192 Select Groups From Directory <\/em>to select the groups to be pulled from the LDAP server. <\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/17b27b82c031dd9cfeb228effc197d05.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 8. Adding groups from the LDAP server<\/p>\n<p>6) In the window that appears, click <em>Retrieve Groups. <\/em>If the groups are successfully pulled, it means the preliminary steps were completed successfully. Otherwise, try another administrator and check the accessibility of ISE with the LDAP server via the LDAP protocol.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/66e2a33754432ed898fbd5a50c3c9caf.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 9. List of retrieved user groups<\/p>\n<p>7) In the tab <em>Attributes <\/em>you can optionally specify which attributes from the LDAP server should be pulled, and in the window <em>Advanced Settings <\/em>enable the option <em>Enable Password Change<\/em>, which will require users to change their password if it has expired or been reset. In any case, click <em>, which takes us back to the page <\/em>to continue.<\/p>\n<p>8) The LDAP server has appeared in the corresponding tab and can be used for access policy formation going forward.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/562760819cfcb601535d032d84267d2f.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 10. List of added LDAP servers<\/p>\n<h2>4. Integration with Active Directory<\/h2>\n<p>1) After adding the Microsoft Active Directory server as an LDAP server, we obtained users, user groups, but no logs. Next, I suggest setting up full integration of AD with Cisco ISE. Go to the tab <em>Administration \u2192 Identity Management \u2192 External Identity Sources \u2192 Active Directory \u2192 Add.&nbsp;<\/em><\/p>\n<p><em><strong>Note: <\/strong><\/em>for successful integration with AD, ISE must be in the domain and have full connectivity to DNS, NTP, and AD servers; otherwise, it will not work.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/f5530a66e45b8da3e84ba0b956ecc8bb.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 11. Adding Active Directory server<\/p>\n<p>2) In the window that appears, enter the domain administrator's credentials and check the box <em>Store Credentials. <\/em>Additionally, you can specify the OU (Organizational Unit) if ISE is in a specific OU. Next, you will need to select the Cisco ISE nodes you want to connect to the domain.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/ed8ee6219b3b89b7043d2bd0383209f6.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 12. Entering credentials<\/p>\n<p>3) Before adding domain controllers, ensure that the PSN in the tab <em>Administration \u2192 System \u2192 Deployment<\/em> has the option enabled <em>Passive Identity Service<\/em>. <strong>PassiveID <\/strong>\u2014 an option that allows translating User to IP and vice versa. PassiveID retrieves information from AD via WMI, special AD agents, or a SPAN port on the switch (not the best option).<\/p>\n<p><em><strong>Note: <\/strong><\/em>to check the status of Passive ID, enter in the ISE console <strong>show application status ise | include PassiveID.<\/strong><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/fdef0f1d9989cecb54e0133311886e15.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 13. Enabling the PassiveID option <\/p>\n<p>4) Go to the tab <em>Administration \u2192 Identity Management \u2192 External Identity Sources \u2192 Active Directory \u2192 PassiveID <\/em>and select the option <em>Add DCs<\/em>. Then, select the necessary domain controllers with checkboxes and click <em>OK.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/0c8e1c03913a6ea2df40ba097f718133.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 14. Adding domain controllers<\/p>\n<p>5) Select the added DC and click the <em>Edit. <\/em>Specify <em>FQDN <\/em>of your DC, domain login and password, as well as the connection option <em>WMI <\/em>or <em>Agent<\/em>. Choose WMI and click <em>OK.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/c484fbbc8c57a11eae3879088acd5186.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 15. Entering domain controller information<\/p>\n<p>6) If WMI is not the preferred method of communication with Active Directory, you can use agent-based methods. The agent-based method means that you can install special agents on the servers that will log login events. There are 2 installation options: automatic and manual. To automatically install the agent in the same tab, <em>PassiveID <\/em>select the item<em> Add Agent \u2192 Deploy New Agent<\/em> (the DC must have Internet access). Then fill in the required fields (agent name, FQDN server, domain administrator login\/password) and click <em>OK.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/9972907c37737e2b20c5e601724f054b.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 16. Automatic installation of the ISE agent<\/p>\n<p>7) For manual installation of the Cisco ISE agent, you need to select the item <em>Register Existing Agent<\/em>. By the way, you can download the agent in the tab <em>Work Centers \u2192 PassiveID \u2192 Providers \u2192 Agents \u2192 Download Agent.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/5ecdabc1fa3b7236b0f88f47bf828576.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 17. Downloading the ISE agent<\/p>\n<p><em><strong>Important: <\/strong><\/em>PassiveID does not read <strong>logoff<\/strong>! The parameter responsible for the timeout is called <strong>user session aging time<\/strong> and is equal to 24 hours by default. Therefore, you should either log off yourself at the end of the workday or write some script that will automatically log off all logged-in users.&nbsp;<\/p>\n<p>To obtain information <strong>logoff<\/strong> uses \u2018Endpoint probes\u2019 \u2014 endpoint probes. Several types of Endpoint probes exist in Cisco ISE: RADIUS, SNMP Trap, SNMP Query, DHCP, DNS, HTTP, Netflow, NMAP Scan. <strong>RADIUS <\/strong>The probe using <strong>CoA <\/strong>(Change of Authorization) packets provides information about user rights changes (for this an embedded <strong>802.1X<\/strong>), while those configured on access switches via SNMP will provide information on connected and disconnected devices.<\/p>\n<p>Below is an example relevant to Cisco ISE + AD configuration without 802.1X and RADIUS: a user is logged into a Windows machine, and without logging off, logs in from another PC via WiFi. In this case, the session on the first PC will remain active until a timeout occurs or a forced logoff takes place. If the devices have different permissions, the last logged-in device will apply its permissions.<\/p>\n<p>8) Additionally in the tab <em>Administration \u2192 Identity Management \u2192 External Identity Sources \u2192 Active Directory \u2192 Groups \u2192 Add \u2192 Select Groups From Directory <\/em>You can select groups from AD that you want to pull into ISE (this was done in item 3 'Adding the LDAP Server'). Select the option <em>Retrieve Groups \u2192 OK<\/em>.&nbsp;<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/044864b12c94528eded7a24b47452c6d.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 18 a). Pulling user groups from Active Directory<\/p>\n<p>9) In the tab <em>Work Centers \u2192 PassiveID \u2192 Overview \u2192 Dashboard<\/em> You can observe the number of active sessions, the number of data sources, agents, and more.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/387389282ba2fe54be4af0e4da37371b.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 19. Monitoring domain user activity<\/p>\n<p>10) In the tab <em>Live Sessions<\/em> the current sessions are displayed. Integration with AD is configured.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2\" src=\"\/wp-content\/uploads\/2020\/09\/85333b48e751c5d9dc9e44364a103dcc.jpg\" style=\"display:block;margin: 0 auto;\" \/>Figure 20. Active sessions of domain users<\/p>\n<h2>5. Conclusion<\/h2>\n<p>This article discussed the topics of creating local users in Cisco ISE, adding LDAP servers, and integrating with Microsoft Active Directory. The next article will cover guest access in a comprehensive guide.<\/p>\n<p>If you have any questions on this topic or need assistance in testing the product, feel free to reach out at <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/cisco\/ise\"><u>this link<\/u><\/a><\/noindex>.<\/p>\n<p>Stay updated through our channels (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\"><u>Telegram<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\"><u>Facebook<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\"><u>VK<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\"><u>TS Solution Blog<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\"><u>Yandex.Zen<\/u><\/a><\/noindex>).<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/520222\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e \u0432\u043e \u0432\u0442\u043e\u0440\u043e\u0439 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u0446\u0438\u043a\u043b\u0430 \u0441\u0442\u0430\u0442\u0435\u0439, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u043c\u0443 Cisco ISE. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435&nbsp; \u0431\u044b\u043b\u0438 \u043e\u0441\u0432\u0435\u0449\u0435\u043d\u044b \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u0438 \u043e\u0442\u043b\u0438\u0447\u0438\u044f Network Access Control (NAC) \u0440\u0435\u0448\u0435\u043d\u0438\u0439 \u043e\u0442 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0445 \u0410\u0410\u0410, \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c Cisco ISE, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0430 \u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u0430. \u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0443\u0433\u043b\u0443\u0431\u0438\u043c\u0441\u044f \u0432 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u0443\u0447\u0435\u0442\u043d\u044b\u0445 \u0437\u0430\u043f\u0438\u0441\u0435\u0439, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u044e LDAP \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u0438 \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u044e \u0441 Microsoft Active Directory, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u043d\u044e\u0430\u043d\u0441\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":95331,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-95330","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Cisco ISE: \u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 LDAP \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432, \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u044f \u0441 AD. \u0427\u0430\u0441\u0442\u044c 2 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-28T05:42:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-28T05:42:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Cisco ISE: Creating users, adding LDAP servers, integrating with AD. Part 2 | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Cisco ISE: \u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 LDAP \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432, \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u044f \u0441 AD. \u0427\u0430\u0441\u0442\u044c 2 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-sozdanie-polzovatelej-dobavlenie-ldap-serverov-integracziya-s-ad-chast-2","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-28T05:42:51+00:00","article:modified_time":"2020-09-28T05:42:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"95330","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:07:33","updated":"2022-09-28 09:57:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=95330"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95330\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/95331"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=95330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=95330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=95330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}