{"id":840,"date":"2016-05-10T20:13:46","date_gmt":"2016-05-10T19:13:46","guid":{"rendered":"http:\/\/www.safekom.pl\/blog\/?p=840"},"modified":"2016-05-10T21:07:08","modified_gmt":"2016-05-10T20:07:08","slug":"lab-ise-jako-radius-dla-paloalto-dla-kont-admina","status":"publish","type":"post","link":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/","title":{"rendered":"LAB &#8211; ISE jako radius dla PaloAlto dla kont Admina"},"content":{"rendered":"<p>Po d\u0142u\u017cszej przerwie wr\u00f3ci\u0142em do integracji Cisco ISE 2.0 z Palo Alto Networks wykorzystuj\u0105c Radiusa z ISE jako punkt uwierzytelniania kont administracyjnych. Wiem, \u017ce zapewne wi\u0119kszo\u015b\u0107 autoryzacji kont administracyjnych opiera si\u0119 o LDAP oraz AD. Natomiast ja jak zawsz\u0119 musz\u0119 kombinowa\u0107 i komplikowa\u0107 scenariusze do labowania, ale dzi\u0119ki takiemu podej\u015bciu jestem w stanie bardziej pozna\u0107 oba systemy.<\/p>\n<h5>Konfiguracja ISE<\/h5>\n<p>przechodzimy do <strong>Policy<\/strong> &#8211;&gt; <strong>Policy Elements<\/strong> &#8211;&gt; <strong>Dictationaries<\/strong> wybieramy <strong>system<\/strong> &#8211;&gt; <strong>radius<\/strong> &#8212;<strong>RADIUS Vendors.\u00a0<\/strong>Tutaj b\u0119dzie nam pomocny\u00a0<a href=\"https:\/\/live.paloaltonetworks.com\/t5\/Configuration-Articles\/RADIUS-Vendor-Specific-Attributes-VSA\/ta-p\/60273\">link<\/a>&#8211; gdzie mamy opisane atrybuty.<br \/>\nklikamy add<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"841\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise01\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png?fit=661%2C269&amp;ssl=1\" data-orig-size=\"661,269\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise01\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png?fit=661%2C269&amp;ssl=1\" class=\"alignnone size-full wp-image-841\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png?resize=661%2C269\" alt=\"palo_ise01\" width=\"661\" height=\"269\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png?w=661&amp;ssl=1 661w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise01.png?resize=300%2C122&amp;ssl=1 300w\" sizes=\"auto, (max-width: 661px) 100vw, 661px\" \/><\/a><\/p>\n<p><strong>Dictionary Name<\/strong>: PaloAlto &#8211; nasza nazwa<br \/>\n<strong>Vendor ID<\/strong>: 25461<\/p>\n<p>klikamy <strong>submit<\/strong><\/p>\n<p>przechodzimy do nowo utworzonego profilu po czym przechodzimy do <strong>Dictionary Attributes.<\/strong>\u00a0Klikamy add<br \/>\nzgodnie z dokumentacj\u0105 PaloAlto. W tej chwili b\u0119dzie nam potrzebny jeden atrybut<br \/>\n<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"842\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise02\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?fit=775%2C359&amp;ssl=1\" data-orig-size=\"775,359\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise02\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?fit=770%2C357&amp;ssl=1\" class=\"alignnone size-full wp-image-842\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?resize=770%2C357\" alt=\"palo_ise02\" width=\"770\" height=\"357\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?w=775&amp;ssl=1 775w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?resize=300%2C139&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise02.png?resize=768%2C356&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/p>\n<p><strong>Attribute Name<\/strong>: PaloAlto-Admin-Role<br \/>\n<strong>Data Type<\/strong>: String<br \/>\n<strong>Direction<\/strong>: Both<br \/>\n<strong>ID<\/strong>: 1<br \/>\nW kroku kolejnym tworzymy profil dla urz\u0105dza\u0144 typu PaloAlto. Przechodzimy do <strong>Administration<\/strong> &#8211;&gt; <strong>Network Resources<\/strong> &#8211;&gt; <strong>Network Device Profiles<\/strong> klikamy Add<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"843\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise03\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?fit=953%2C509&amp;ssl=1\" data-orig-size=\"953,509\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise03\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?fit=770%2C411&amp;ssl=1\" class=\"alignnone size-full wp-image-843\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?resize=770%2C411\" alt=\"palo_ise03\" width=\"770\" height=\"411\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?w=953&amp;ssl=1 953w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?resize=300%2C160&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise03.png?resize=768%2C410&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><br \/>\nDodajemy nasze urz\u0105dzenie do ISE, przechodzimy do <strong>Administration<\/strong> &#8211;&gt; <strong>Network Resources<\/strong> &#8211;&gt; <strong>Network Devices<\/strong> klikamy Add<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"849\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise09\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?fit=853%2C565&amp;ssl=1\" data-orig-size=\"853,565\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise09\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?fit=770%2C510&amp;ssl=1\" class=\"alignnone size-full wp-image-849\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?resize=770%2C510\" alt=\"palo_ise09\" width=\"770\" height=\"510\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?w=853&amp;ssl=1 853w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?resize=300%2C199&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise09.png?resize=768%2C509&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><br \/>\nPodajemy dane:<br \/>\n<strong>Name<\/strong>: nazw\u0119 dla naszego urz\u0105dzenia<br \/>\n<strong>IP Address<\/strong>: podajemy adres ip, z kt\u00f3rego nasze urz\u0105dzenie b\u0119dzie si\u0119 komunikowa\u0142o z serwerem ISE<br \/>\n<strong>Device Profile<\/strong>: wybieramy nasz profil dla urz\u0105dze\u0144 Palo<br \/>\n<strong>Device Type<\/strong>: ja stworzy\u0142em oddzielne repo dla urz\u0105dz\u0119\u0144 tego typu<br \/>\n<strong>Location<\/strong>: r\u00f3wnie\u017c podzieli\u0142em na lokalizacj\u0119<br \/>\nWybieramy: <strong>RADIUS Authentication Settings<\/strong><br \/>\nw polu <strong>Shared Secret<\/strong> wpisujemy nasze has\u0142o, kt\u00f3re b\u0119dzie wykorzystywane do po\u0142\u0105czenia PALO do ISE<\/p>\n<p>Wybieramy grup\u0119 AD, w \u00a0kt\u00f3rej b\u0119d\u0105 u\u017cytkownicy mog\u0105cy\u00a0zalogowa\u0107 si\u0119 na Palo<\/p>\n<p>Przechodzimy do <strong>Administration<\/strong> &#8211;&gt;<strong> Indetity Management<\/strong> &#8211;&gt; <strong>External Identity Soures,<\/strong> wybieramy <strong>Active Direcory<\/strong>\u00a0oraz nasz punkt spi\u0119cia z naszym AD. Tam wybieramy <strong>Groups,\u00a0<\/strong>dodajemy Add z menu <strong>Select Dictionary Groups<\/strong>\u00a0po czym otworzy si\u0119 okno, w kt\u00f3rym mo\u017cemy wyszuka\u0107 nasz\u0105 grup\u0119 dodaj\u0105c j\u0105 do ISE.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"844\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise04\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?fit=898%2C565&amp;ssl=1\" data-orig-size=\"898,565\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise04\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?fit=770%2C484&amp;ssl=1\" class=\"alignnone size-full wp-image-844\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?resize=770%2C484\" alt=\"palo_ise04\" width=\"770\" height=\"484\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?w=898&amp;ssl=1 898w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?resize=300%2C189&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise04.png?resize=768%2C483&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>Tworzymy profil dozwolonych protoko\u0142\u00f3w komunikacji PALO ISE, przechodzimy do <strong>Policy<\/strong> &#8211;&gt; <strong>Policy Elements<\/strong> &#8211;&gt; <strong>Results<\/strong> &#8211;&gt; <strong>Authentication<\/strong> &#8211;&gt; <strong>Allowed Protocols,<\/strong> klikamy Add<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"845\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise05\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png?fit=443%2C357&amp;ssl=1\" data-orig-size=\"443,357\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise05\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png?fit=443%2C357&amp;ssl=1\" class=\"alignnone size-full wp-image-845\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png?resize=443%2C357\" alt=\"palo_ise05\" width=\"443\" height=\"357\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png?w=443&amp;ssl=1 443w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise05.png?resize=300%2C242&amp;ssl=1 300w\" sizes=\"auto, (max-width: 443px) 100vw, 443px\" \/><\/a><\/p>\n<p>Tworzymy profil autoryzacyjny, przechodzimy do <strong>Policy<\/strong> &#8211;&gt; <strong>Policy Elements<\/strong> &#8211;&gt; <strong>Results<\/strong> &#8211;&gt; <strong>Authorization<\/strong> &#8211;&gt; <strong>Authoriztion Profiles,<\/strong> kliamy Add<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"846\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise06\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?fit=797%2C535&amp;ssl=1\" data-orig-size=\"797,535\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise06\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?fit=770%2C517&amp;ssl=1\" class=\"alignnone size-full wp-image-846\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?resize=770%2C517\" alt=\"palo_ise06\" width=\"770\" height=\"517\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?w=797&amp;ssl=1 797w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?resize=300%2C201&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?resize=768%2C516&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise06.png?resize=272%2C182&amp;ssl=1 272w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><br \/>\nw polu <strong>Advanced Attributes Settings<\/strong> wybieramy z menu <strong>PaloAlto<\/strong> &#8211;&gt; <strong>PaloAlto-Admin-Role,<\/strong> w polu obok wpisujemy nazw\u0119 naszego profilu z Palo, kt\u00f3ry p\u00f3\u017aniej zostanie skonfigurowany na Palo.<\/p>\n<p>W polu <strong>Attributes Details<\/strong> mamy taki wynik:<\/p>\n<pre class=\"lang:sh decode:true \">Access Type = ACCESS_ACCEPT\r\nPaloAlto-Admin-Role = admin-radius<\/pre>\n<p>przechodzimy do utworzenia regu\u0142y autoryzacyjnej, gdzie idziemy do <strong>Polcy<\/strong> &#8211;&gt; <strong>Authorization<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"847\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise07\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?fit=1311%2C163&amp;ssl=1\" data-orig-size=\"1311,163\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise07\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?fit=770%2C95&amp;ssl=1\" class=\"alignnone size-full wp-image-847\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?resize=770%2C96\" alt=\"palo_ise07\" width=\"770\" height=\"96\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?w=1311&amp;ssl=1 1311w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?resize=300%2C37&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?resize=768%2C95&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise07.png?resize=1024%2C127&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>dodajemy now\u0105 rul\u0119\u00a0gdzie:<br \/>\n<strong>Rule Name<\/strong>: nasza nazwa regu\u0142y<br \/>\nwarunki:<br \/>\nIf ANY and ISE-SRV:memberOf maches CN=PA-admin-full,CN=Users,DC=safekom,DC=pl<br \/>\nand DEVICE:Device Type Equals Device Type#All Device Types#Palo<br \/>\nthen Palo-auth<\/p>\n<p>&nbsp;<\/p>\n<h5>Konfiguracja Palo<\/h5>\n<p>Prszyszed\u0142 czas na konfiguracj\u0119\u00a0naszego Palo. Po zalogowaniu si\u0119 przechodzimy do <strong>Device<\/strong> &#8211;&gt; <strong>Server Profiles<\/strong> &#8211;&gt; <strong>Radius,<\/strong> dodajemy nowy profil z ISE<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"848\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise08\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?fit=985%2C540&amp;ssl=1\" data-orig-size=\"985,540\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise08\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?fit=770%2C422&amp;ssl=1\" class=\"alignnone size-full wp-image-848\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?resize=770%2C422\" alt=\"palo_ise08\" width=\"770\" height=\"422\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?w=985&amp;ssl=1 985w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?resize=300%2C164&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise08.png?resize=768%2C421&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>gdzie:<\/p>\n<p><strong>Profil Name<\/strong>: nasz profil Radiusa<\/p>\n<p>w polu <strong>servers<\/strong> dodajemy nasze serwery radiusa (w mym przypadku jest to jeden serwer)<\/p>\n<p><strong>Name:\u00a0<\/strong>nasza nazwa rozpoznawcza<\/p>\n<p><strong>RADIUS Server<\/strong>: adres IP lub FQDN naszego radiusa<\/p>\n<p><strong>Secret<\/strong>: nasze ustawione has\u0142o<\/p>\n<p><strong>Port<\/strong>: Standardowo 1812<\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">set shared server-profile radius ISE server ISE01 secret -AQ==gPzxJUAM1wLKKOPC5tJg+lHyn0A=aloUXPMeEZ6yM\/xJpgEVLA==\r\nset shared server-profile radius ISE server ISE01 port 1812\r\nset shared server-profile radius ISE server ISE01 ip-address 192.168.1.55<\/pre>\n<p>Tworzymy profil Admin Roles &#8211; dzi\u0119ki temu profilowi mo\u017cliwe b\u0119dzie zalogowanie si\u0119 u\u017cytkownika z odpowiednimi uprawnieniami.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"850\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise10\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?fit=1030%2C581&amp;ssl=1\" data-orig-size=\"1030,581\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise10\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?fit=770%2C435&amp;ssl=1\" class=\"alignnone size-full wp-image-850\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?resize=770%2C434\" alt=\"palo_ise10\" width=\"770\" height=\"434\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?w=1030&amp;ssl=1 1030w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?resize=300%2C169&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?resize=768%2C433&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise10.png?resize=1024%2C578&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>W tym miejscu wa\u017cne jest aby nazwa profilu by\u0142a taka sama jak zdefiniowali\u015bmy j\u0105 na serwerze ISE <strong>admin-radius<\/strong><\/p>\n<p>Cli<\/p>\n<pre class=\"lang:sh decode:true\">set shared admin-role admin-radius role device cli superuser\r\nset shared admin-role admin-radius role device webui dashboard enable\r\nset shared admin-role admin-radius role device webui acc enable\r\nset shared admin-role admin-radius role device webui monitor logs traffic enable\r\nset shared admin-role admin-radius role device webui monitor logs threat enable\r\nset shared admin-role admin-radius role device webui monitor logs url enable\r\nset shared admin-role admin-radius role device webui monitor logs wildfire enable\r\nset shared admin-role admin-radius role device webui monitor logs data-filtering enable\r\nset shared admin-role admin-radius role device webui monitor logs hipmatch enable\r\nset shared admin-role admin-radius role device webui monitor logs configuration enable\r\nset shared admin-role admin-radius role device webui monitor logs system enable\r\nset shared admin-role admin-radius role device webui monitor logs alarm enable\r\nset shared admin-role admin-radius role device webui monitor automated-correlation-engine correlation-objects enable\r\nset shared admin-role admin-radius role device webui monitor automated-correlation-engine correlated-events enable\r\nset shared admin-role admin-radius role device webui monitor packet-capture enable\r\nset shared admin-role admin-radius role device webui monitor app-scope enable\r\nset shared admin-role admin-radius role device webui monitor session-browser enable\r\nset shared admin-role admin-radius role device webui monitor botnet enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports manage-pdf-summary enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports pdf-summary-reports enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports user-activity-report enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports saas-application-usage-report enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports report-groups enable\r\nset shared admin-role admin-radius role device webui monitor pdf-reports email-scheduler enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports application-statistics enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports data-filtering-log enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports threat-log enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports threat-summary enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports traffic-log enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports traffic-summary enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports url-log enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports url-summary enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports hipmatch enable\r\nset shared admin-role admin-radius role device webui monitor custom-reports wildfire-log enable\r\nset shared admin-role admin-radius role device webui monitor view-custom-reports enable\r\nset shared admin-role admin-radius role device webui monitor application-reports enable\r\nset shared admin-role admin-radius role device webui monitor threat-reports enable\r\nset shared admin-role admin-radius role device webui monitor url-filtering-reports enable\r\nset shared admin-role admin-radius role device webui monitor traffic-reports enable\r\nset shared admin-role admin-radius role device webui policies security-rulebase enable\r\nset shared admin-role admin-radius role device webui policies nat-rulebase enable\r\nset shared admin-role admin-radius role device webui policies qos-rulebase enable\r\nset shared admin-role admin-radius role device webui policies pbf-rulebase enable\r\nset shared admin-role admin-radius role device webui policies ssl-decryption-rulebase enable\r\nset shared admin-role admin-radius role device webui policies application-override-rulebase enable\r\nset shared admin-role admin-radius role device webui policies captive-portal-rulebase enable\r\nset shared admin-role admin-radius role device webui policies dos-rulebase enable\r\nset shared admin-role admin-radius role device webui objects addresses enable\r\nset shared admin-role admin-radius role device webui objects address-groups enable\r\nset shared admin-role admin-radius role device webui objects regions enable\r\nset shared admin-role admin-radius role device webui objects applications enable\r\nset shared admin-role admin-radius role device webui objects application-groups enable\r\nset shared admin-role admin-radius role device webui objects application-filters enable\r\nset shared admin-role admin-radius role device webui objects services enable\r\nset shared admin-role admin-radius role device webui objects service-groups enable\r\nset shared admin-role admin-radius role device webui objects tags enable\r\nset shared admin-role admin-radius role device webui objects global-protect hip-objects enable\r\nset shared admin-role admin-radius role device webui objects global-protect hip-profiles enable\r\nset shared admin-role admin-radius role device webui objects dynamic-block-lists enable\r\nset shared admin-role admin-radius role device webui objects custom-objects data-patterns enable\r\nset shared admin-role admin-radius role device webui objects custom-objects spyware enable\r\nset shared admin-role admin-radius role device webui objects custom-objects vulnerability enable\r\nset shared admin-role admin-radius role device webui objects custom-objects url-category enable\r\nset shared admin-role admin-radius role device webui objects security-profiles antivirus enable\r\nset shared admin-role admin-radius role device webui objects security-profiles anti-spyware enable\r\nset shared admin-role admin-radius role device webui objects security-profiles vulnerability-protection enable\r\nset shared admin-role admin-radius role device webui objects security-profiles url-filtering enable\r\nset shared admin-role admin-radius role device webui objects security-profiles file-blocking enable\r\nset shared admin-role admin-radius role device webui objects security-profiles wildfire-analysis enable\r\nset shared admin-role admin-radius role device webui objects security-profiles data-filtering enable\r\nset shared admin-role admin-radius role device webui objects security-profiles dos-protection enable\r\nset shared admin-role admin-radius role device webui objects security-profile-groups enable\r\nset shared admin-role admin-radius role device webui objects log-forwarding enable\r\nset shared admin-role admin-radius role device webui objects decryption-profile enable\r\nset shared admin-role admin-radius role device webui objects schedules enable\r\nset shared admin-role admin-radius role device webui network interfaces enable\r\nset shared admin-role admin-radius role device webui network zones enable\r\nset shared admin-role admin-radius role device webui network vlans enable\r\nset shared admin-role admin-radius role device webui network virtual-wires enable\r\nset shared admin-role admin-radius role device webui network virtual-routers enable\r\nset shared admin-role admin-radius role device webui network ipsec-tunnels enable\r\nset shared admin-role admin-radius role device webui network dhcp enable\r\nset shared admin-role admin-radius role device webui network dns-proxy enable\r\nset shared admin-role admin-radius role device webui network global-protect portals enable\r\nset shared admin-role admin-radius role device webui network global-protect gateways enable\r\nset shared admin-role admin-radius role device webui network global-protect mdm enable\r\nset shared admin-role admin-radius role device webui network global-protect device-block-list enable\r\nset shared admin-role admin-radius role device webui network qos enable\r\nset shared admin-role admin-radius role device webui network lldp enable\r\nset shared admin-role admin-radius role device webui network network-profiles gp-app-ipsec-crypto enable\r\nset shared admin-role admin-radius role device webui network network-profiles ike-gateways enable\r\nset shared admin-role admin-radius role device webui network network-profiles ipsec-crypto enable\r\nset shared admin-role admin-radius role device webui network network-profiles ike-crypto enable\r\nset shared admin-role admin-radius role device webui network network-profiles tunnel-monitor enable\r\nset shared admin-role admin-radius role device webui network network-profiles interface-mgmt enable\r\nset shared admin-role admin-radius role device webui network network-profiles zone-protection enable\r\nset shared admin-role admin-radius role device webui network network-profiles qos-profile enable\r\nset shared admin-role admin-radius role device webui network network-profiles lldp-profile enable\r\nset shared admin-role admin-radius role device webui network network-profiles bfd-profile enable\r\nset shared admin-role admin-radius role device webui device setup management enable\r\nset shared admin-role admin-radius role device webui device setup operations enable\r\nset shared admin-role admin-radius role device webui device setup services enable\r\nset shared admin-role admin-radius role device webui device setup content-id enable\r\nset shared admin-role admin-radius role device webui device setup wildfire enable\r\nset shared admin-role admin-radius role device webui device setup session enable\r\nset shared admin-role admin-radius role device webui device setup hsm enable\r\nset shared admin-role admin-radius role device webui device high-availability enable\r\nset shared admin-role admin-radius role device webui device config-audit enable\r\nset shared admin-role admin-radius role device webui device administrators read-only\r\nset shared admin-role admin-radius role device webui device admin-roles read-only\r\nset shared admin-role admin-radius role device webui device authentication-profile enable\r\nset shared admin-role admin-radius role device webui device authentication-sequence enable\r\nset shared admin-role admin-radius role device webui device user-identification enable\r\nset shared admin-role admin-radius role device webui device vm-info-source enable\r\nset shared admin-role admin-radius role device webui device certificate-management certificates enable\r\nset shared admin-role admin-radius role device webui device certificate-management certificate-profile enable\r\nset shared admin-role admin-radius role device webui device certificate-management ocsp-responder enable\r\nset shared admin-role admin-radius role device webui device certificate-management ssl-tls-service-profile enable\r\nset shared admin-role admin-radius role device webui device certificate-management scep enable\r\nset shared admin-role admin-radius role device webui device block-pages enable\r\nset shared admin-role admin-radius role device webui device log-settings system enable\r\nset shared admin-role admin-radius role device webui device log-settings config enable\r\nset shared admin-role admin-radius role device webui device log-settings hipmatch enable\r\nset shared admin-role admin-radius role device webui device log-settings cc-alarm enable\r\nset shared admin-role admin-radius role device webui device log-settings manage-log enable\r\nset shared admin-role admin-radius role device webui device server-profile snmp-trap enable\r\nset shared admin-role admin-radius role device webui device server-profile syslog enable\r\nset shared admin-role admin-radius role device webui device server-profile email enable\r\nset shared admin-role admin-radius role device webui device server-profile netflow enable\r\nset shared admin-role admin-radius role device webui device server-profile radius enable\r\nset shared admin-role admin-radius role device webui device server-profile tacplus enable\r\nset shared admin-role admin-radius role device webui device server-profile ldap enable\r\nset shared admin-role admin-radius role device webui device server-profile kerberos enable\r\nset shared admin-role admin-radius role device webui device local-user-database users enable\r\nset shared admin-role admin-radius role device webui device local-user-database user-groups enable\r\nset shared admin-role admin-radius role device webui device scheduled-log-export enable\r\nset shared admin-role admin-radius role device webui device software enable\r\nset shared admin-role admin-radius role device webui device global-protect-client enable\r\nset shared admin-role admin-radius role device webui device dynamic-updates enable\r\nset shared admin-role admin-radius role device webui device licenses enable\r\nset shared admin-role admin-radius role device webui device support enable\r\nset shared admin-role admin-radius role device webui device master-key enable\r\nset shared admin-role admin-radius role device webui privacy show-full-ip-addresses enable\r\nset shared admin-role admin-radius role device webui privacy show-user-names-in-logs-and-reports enable\r\nset shared admin-role admin-radius role device webui privacy view-pcap-files enable\r\nset shared admin-role admin-radius role device webui validate enable\r\nset shared admin-role admin-radius role device webui commit enable\r\nset shared admin-role admin-radius role device webui global system-alarms enable\r\nset shared admin-role admin-radius role device xmlapi report enable\r\nset shared admin-role admin-radius role device xmlapi log enable\r\nset shared admin-role admin-radius role device xmlapi config enable\r\nset shared admin-role admin-radius role device xmlapi op enable\r\nset shared admin-role admin-radius role device xmlapi commit enable\r\nset shared admin-role admin-radius role device xmlapi user-id enable\r\nset shared admin-role admin-radius role device xmlapi export enable\r\nset shared admin-role admin-radius role device xmlapi import enable<\/pre>\n<p>Tworzymy profil dla <strong>Authentication Profile,<\/strong> gdzie b\u0119dziemy wykorzystywa\u0107 nasz profil dla ISE:<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"851\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise11\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?fit=1359%2C546&amp;ssl=1\" data-orig-size=\"1359,546\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?fit=770%2C309&amp;ssl=1\" class=\"alignnone size-full wp-image-851\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?resize=770%2C309\" alt=\"palo_ise11\" width=\"770\" height=\"309\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?w=1359&amp;ssl=1 1359w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?resize=300%2C121&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?resize=768%2C309&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise11.png?resize=1024%2C411&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><br \/>\nw <strong>Type<\/strong> wybieramy RADIUS<br \/>\n<strong>Server Profile<\/strong> wybieramy nasz profil ISE<br \/>\nW <strong>Advanced<\/strong><br \/>\nw <strong>Allow List<\/strong> dajemy <strong>all<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"852\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise12\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png?fit=599%2C500&amp;ssl=1\" data-orig-size=\"599,500\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png?fit=599%2C500&amp;ssl=1\" class=\"alignnone size-full wp-image-852\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png?resize=599%2C500\" alt=\"palo_ise12\" width=\"599\" height=\"500\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png?w=599&amp;ssl=1 599w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise12.png?resize=300%2C250&amp;ssl=1 300w\" sizes=\"auto, (max-width: 599px) 100vw, 599px\" \/><\/a><\/p>\n<p>Cli<\/p>\n<pre class=\"lang:sh decode:true\">set shared authentication-profile ISE method radius server-profile ISE\r\nset shared authentication-profile ISE allow-list all\r\nset shared authentication-profile ISE lockout lockout-time 1\r\nset shared authentication-profile ISE lockout failed-attempts 5<\/pre>\n<p>Po wykonaniu commitu pr\u00f3bujemy zalogowa\u0107 si\u0119 do urz\u0105dzenia po ssh<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"853\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise13\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png?fit=496%2C64&amp;ssl=1\" data-orig-size=\"496,64\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise13\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png?fit=496%2C64&amp;ssl=1\" class=\"alignnone size-full wp-image-853\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png?resize=496%2C64\" alt=\"palo_ise13\" width=\"496\" height=\"64\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png?w=496&amp;ssl=1 496w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise13.png?resize=300%2C39&amp;ssl=1 300w\" sizes=\"auto, (max-width: 496px) 100vw, 496px\" \/><\/a><\/p>\n<p>w logach PA widzimy:<\/p>\n<p>Web<\/p>\n<p>wyszukujemy po:<\/p>\n<pre class=\"lang:sh decode:true\">( object eq auth )<\/pre>\n<p>lub jak ni\u017cej na screenie:<\/p>\n<pre class=\"lang:sh decode:true \">( eventid eq auth-success )<\/pre>\n<p>Jak chcemy wyszuka\u0107 b\u0142\u0119dne autoryzacje\u00a0stosujemy filtr:<\/p>\n<pre class=\"lang:sh decode:true \">( eventid eq auth-fail )<\/pre>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"862\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise18-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?fit=957%2C418&amp;ssl=1\" data-orig-size=\"957,418\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise18\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?fit=770%2C336&amp;ssl=1\" class=\"alignnone size-full wp-image-862\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?resize=770%2C336\" alt=\"palo_ise18\" width=\"770\" height=\"336\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?w=957&amp;ssl=1 957w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?resize=300%2C131&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise18-1.png?resize=768%2C335&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">michal-adminpa@PA-VM&gt; show log system eventid equal auth-success\r\nTime                Severity Subtype Object EventID ID Description\r\n===============================================================================\r\n2016\/05\/10 13:00:16 info     general auth   auth-su 0  authenticated for user 'michal-adminpa'.   auth profile 'auth', vsys 'shared', server profile\r\n 'ISE', server address '192.168.1.55', From: 192.168.1.10.<\/pre>\n<p>&nbsp;<\/p>\n<p>Taki u\u017cytkownik nie mo\u017ce dodawa\u0107 kont lokalnych i modyfikowa\u0107 ich oraz dodawa\u0107\/modyfkowa\u0107 <strong>Admin Rulses\u00a0<\/strong>tak jak wida\u0107 ni\u017cej pola add oraz delete mam wyszarzane:<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"857\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise17\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?fit=1361%2C665&amp;ssl=1\" data-orig-size=\"1361,665\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise17\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?fit=770%2C376&amp;ssl=1\" class=\"alignnone size-full wp-image-857\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?resize=770%2C376\" alt=\"palo_ise17\" width=\"770\" height=\"376\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?w=1361&amp;ssl=1 1361w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?resize=300%2C147&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?resize=768%2C375&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise17.png?resize=1024%2C500&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><br \/>\nAby umo\u017cliwi\u0107 dost\u0119p na pe\u0142nych prawach musimy utworzy\u0107 konto Administratora:<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"855\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise15\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png?fit=649%2C242&amp;ssl=1\" data-orig-size=\"649,242\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise15\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png?fit=649%2C242&amp;ssl=1\" class=\"alignnone size-full wp-image-855\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png?resize=649%2C242\" alt=\"palo_ise15\" width=\"649\" height=\"242\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png?w=649&amp;ssl=1 649w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise15.png?resize=300%2C112&amp;ssl=1 300w\" sizes=\"auto, (max-width: 649px) 100vw, 649px\" \/><\/a><\/p>\n<p>gdzie <strong>Name\u00a0<\/strong>jest naszym userem, kt\u00f3ry jest w Radiusie.<\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">set mgt-config users michal permissions role-based superuser yes\r\nset mgt-config users michal authentication-profile ISE<\/pre>\n<p>Po takim zabiegu mamy konto z full uprawnieniami, zalogowany administrator ju\u017c mo\u017ce modyfikowa\u0107 <strong>Admin Roles<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"859\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/attachment\/palo_ise19\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?fit=1362%2C664&amp;ssl=1\" data-orig-size=\"1362,664\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ise19\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?fit=770%2C375&amp;ssl=1\" class=\"alignnone size-full wp-image-859\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?resize=770%2C375\" alt=\"palo_ise19\" width=\"770\" height=\"375\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?w=1362&amp;ssl=1 1362w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?resize=300%2C146&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?resize=768%2C374&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/05\/palo_ise19.png?resize=1024%2C499&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>Poprzednie wpisy dotycz\u0105ce ISE:<\/p>\n<ol>\n<li><a href=\"http:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-2-0-w-labie-cz1\/\">LAB \u2013 Cisco ISE 2.0 w Labie \u2013 cz1<\/a><\/li>\n<li><a href=\"http:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-join-ad-cz-2\/\">LAB \u2013 Cisco ISE join AD cz.2<\/a><\/li>\n<li><a href=\"http:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-aaa-dla-junipera\/\">Lab \u2013 Cisco ISE \u2013 AAA dla Junosa<\/a><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Po d\u0142u\u017cszej przerwie wr\u00f3ci\u0142em do integracji Cisco ISE 2.0 z Palo Alto Networks wykorzystuj\u0105c Radiusa z ISE jako punkt uwierzytelniania kont administracyjnych. Wiem, \u017ce zapewne wi\u0119kszo\u015b\u0107 autoryzacji kont administracyjnych opiera si\u0119 o LDAP oraz AD. Natomiast ja jak zawsz\u0119 musz\u0119 kombinowa\u0107 i komplikowa\u0107 scenariusze do labowania, ale dzi\u0119ki takiemu podej\u015bciu jestem w stanie bardziej pozna\u0107 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"LAB - ISE jako radius dla PaloAlto dla kont Admina [in Polish lang. how to integrate Cisco ISE with palo alto netowrks for admin account ]","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[4,84,78],"tags":[250,150,244,246,245,243,248,138,81,80,140,247,86,249],"class_list":["post-840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco","category-lab","category-palo-alto","tag-250","tag-aaa","tag-admin","tag-admin-role","tag-authentication-profile","tag-cisco-ise-2-0","tag-dictionary","tag-ise","tag-palo-alto-networks","tag-paloalto","tag-radius","tag-server-profile","tag-user","tag-vendor-id-25461"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/\" \/>\n<meta property=\"og:locale\" content=\"pl_PL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog\" \/>\n<meta property=\"og:description\" content=\"Po d\u0142u\u017cszej przerwie wr\u00f3ci\u0142em do integracji Cisco ISE 2.0 z Palo Alto Networks wykorzystuj\u0105c Radiusa z ISE jako punkt uwierzytelniania kont administracyjnych. Wiem, \u017ce zapewne wi\u0119kszo\u015b\u0107 autoryzacji kont administracyjnych opiera si\u0119 o LDAP oraz AD. Natomiast ja jak zawsz\u0119 musz\u0119 kombinowa\u0107 i komplikowa\u0107 scenariusze do labowania, ale dzi\u0119ki takiemu podej\u015bciu jestem w stanie bardziej pozna\u0107 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/\" \/>\n<meta property=\"og:site_name\" content=\"SafeKom Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/safekompl\" \/>\n<meta property=\"article:published_time\" content=\"2016-05-10T19:13:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-05-10T20:07:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"566\" \/>\n\t<meta property=\"og:image:height\" content=\"680\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:site\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:label1\" content=\"Napisane przez\" \/>\n\t<meta name=\"twitter:data1\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Szacowany czas czytania\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/\"},\"author\":{\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\"},\"headline\":\"LAB &#8211; ISE jako radius dla PaloAlto dla kont Admina\",\"datePublished\":\"2016-05-10T19:13:46+00:00\",\"dateModified\":\"2016-05-10T20:07:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/\"},\"wordCount\":740,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"keywords\":[\"25461\",\"aaa\",\"admin\",\"admin-role\",\"authentication-profile\",\"Cisco ISE 2.0\",\"Dictionary\",\"ISE\",\"Palo Alto Networks\",\"PaloAlto\",\"Radius\",\"server-profile\",\"user\",\"Vendor ID: 25461\"],\"articleSection\":[\"Cisco\",\"Lab\",\"Palo Alto\"],\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/\",\"name\":\"LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"datePublished\":\"2016-05-10T19:13:46+00:00\",\"dateModified\":\"2016-05-10T20:07:08+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#breadcrumb\"},\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"width\":566,\"height\":680},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"LAB &#8211; ISE jako radius dla PaloAlto dla kont Admina\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"name\":\"SafeKom Blog\",\"description\":\"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pl-PL\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\",\"name\":\"SafeKom Blog\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"SafeKom Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/safekompl\",\"https:\\\/\\\/x.com\\\/MIwaczuk\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michaliwanczuk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\",\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"caption\":\"Micha\u0142 Iwa\u0144czuk\"},\"description\":\"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\\\/7\\\/365.\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/","og_locale":"pl_PL","og_type":"article","og_title":"LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog","og_description":"Po d\u0142u\u017cszej przerwie wr\u00f3ci\u0142em do integracji Cisco ISE 2.0 z Palo Alto Networks wykorzystuj\u0105c Radiusa z ISE jako punkt uwierzytelniania kont administracyjnych. Wiem, \u017ce zapewne wi\u0119kszo\u015b\u0107 autoryzacji kont administracyjnych opiera si\u0119 o LDAP oraz AD. Natomiast ja jak zawsz\u0119 musz\u0119 kombinowa\u0107 i komplikowa\u0107 scenariusze do labowania, ale dzi\u0119ki takiemu podej\u015bciu jestem w stanie bardziej pozna\u0107 [&hellip;]","og_url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/","og_site_name":"SafeKom Blog","article_publisher":"https:\/\/www.facebook.com\/safekompl","article_published_time":"2016-05-10T19:13:46+00:00","article_modified_time":"2016-05-10T20:07:08+00:00","og_image":[{"width":566,"height":680,"url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","type":"image\/png"}],"author":"Micha\u0142 Iwa\u0144czuk","twitter_card":"summary_large_image","twitter_creator":"@MIwaczuk","twitter_site":"@MIwaczuk","twitter_misc":{"Napisane przez":"Micha\u0142 Iwa\u0144czuk","Szacowany czas czytania":"12 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#article","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/"},"author":{"name":"Micha\u0142 Iwa\u0144czuk","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181"},"headline":"LAB &#8211; ISE jako radius dla PaloAlto dla kont Admina","datePublished":"2016-05-10T19:13:46+00:00","dateModified":"2016-05-10T20:07:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/"},"wordCount":740,"commentCount":0,"publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","keywords":["25461","aaa","admin","admin-role","authentication-profile","Cisco ISE 2.0","Dictionary","ISE","Palo Alto Networks","PaloAlto","Radius","server-profile","user","Vendor ID: 25461"],"articleSection":["Cisco","Lab","Palo Alto"],"inLanguage":"pl-PL","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/","url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/","name":"LAB - ISE jako radius dla PaloAlto dla kont Admina - SafeKom Blog","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#primaryimage"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","datePublished":"2016-05-10T19:13:46+00:00","dateModified":"2016-05-10T20:07:08+00:00","breadcrumb":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#breadcrumb"},"inLanguage":"pl-PL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/"]}]},{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#primaryimage","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","width":566,"height":680},{"@type":"BreadcrumbList","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ise-jako-radius-dla-paloalto-dla-kont-admina\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.safekom.pl\/blog\/"},{"@type":"ListItem","position":2,"name":"LAB &#8211; ISE jako radius dla PaloAlto dla kont Admina"}]},{"@type":"WebSite","@id":"https:\/\/www.safekom.pl\/blog\/#website","url":"https:\/\/www.safekom.pl\/blog\/","name":"SafeKom Blog","description":"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem","publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.safekom.pl\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pl-PL"},{"@type":"Organization","@id":"https:\/\/www.safekom.pl\/blog\/#organization","name":"SafeKom Blog","url":"https:\/\/www.safekom.pl\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"SafeKom Blog"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/safekompl","https:\/\/x.com\/MIwaczuk","https:\/\/www.linkedin.com\/in\/michaliwanczuk\/"]},{"@type":"Person","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181","name":"Micha\u0142 Iwa\u0144czuk","image":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","caption":"Micha\u0142 Iwa\u0144czuk"},"description":"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\/7\/365.","url":"https:\/\/www.safekom.pl\/blog\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/p7i9ri-dy","jetpack-related-posts":[{"id":494,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-join-ad-cz-2\/","url_meta":{"origin":840,"position":0},"title":"LAB &#8211; Cisco ISE join AD cz.2","author":"Micha\u0142 Iwa\u0144czuk","date":"02.02.2016","format":false,"excerpt":"W tej cz\u0119\u015bci opisz\u0119 jak ISE pod\u0142\u0105czy\u0107 do Active Directory: Dane domeny: Domena safekom.pl Kontroler Domeny AD01.safekom.pl Logujemy si\u0119 do ISE: przechodzimy do Administration -->\u00a0External Identity Sources wybieramy Active Directory po lewej stronie: Klikamy add w polu Join Point Name - musimy da\u0107 inn\u0105 nazw\u0119 ni\u017c nazwa naszego serwera ISE\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/09\/cisco-logo.png?fit=400%2C300&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":519,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-aaa-dla-junipera\/","url_meta":{"origin":840,"position":1},"title":"Lab &#8211; Cisco ISE &#8211; AAA dla Junosa","author":"Micha\u0142 Iwa\u0144czuk","date":"09.02.2016","format":false,"excerpt":"W poprzednich wpisach opisa\u0142em jak zainstalowa\u0107 oraz jak pod\u0142\u0105czy\u0107 do AD ISE. Poni\u017cej opisz\u0119 jak wykorzysta\u0107 ISE jak radius kt\u00f3ry b\u0119dzie serwowa\u0107 u\u017cytkownik\u00f3w do logowania po ssh i www dla urz\u0105dze\u0144 Juniper pod systemem Junos. Jak centralne repozytorium u\u017cytkownik\u00f3w b\u0119dzie s\u0142u\u017cy\u0107 AD. Mam nadziej\u0119 \u017ce komu\u015b si\u0119 przyda. Bierzemy si\u0119\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":481,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-cisco-ise-2-0-w-labie-cz1\/","url_meta":{"origin":840,"position":2},"title":"LAB &#8211; Cisco ISE 2.0 w Labie &#8211; cz1","author":"Micha\u0142 Iwa\u0144czuk","date":"02.02.2016","format":false,"excerpt":"Postanowi\u0142em pozna\u0107 co to jest oraz z czym to si\u0119 je - ISE w wersji 2.0. Uda\u0142o mi si\u0119 zdoby\u0107 wersj\u0119 demonstracyjn\u0105 na 90dni z pe\u0142n\u0105 funkcjonalno\u015bci\u0105. \u00a0Poni\u017cej przedstawi\u0119 jak instaluj\u0119 w labie. Importujemy plik ova do Workstation Wybieramy file --> open wybieramy nasz plik ova, poni\u017cej kolejny ju\u017c krok\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/09\/cisco-logo.png?fit=400%2C300&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":41,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/cisco-catalyst-polityka-hasel\/","url_meta":{"origin":840,"position":3},"title":"Cisco catalyst &#8211; polityka hase\u0142","author":"Micha\u0142 Iwa\u0144czuk","date":"20.04.2015","format":false,"excerpt":"Ostatnio dosta\u0142em za zadanie ustawienie polityk\u0119 hase\u0142 na Switch'u Cisco poni\u017cej config kt\u00f3ry ustawia polityk\u0119 hase\u0142: aaa new-model aaa authentication login default local aaa authorization exec default local aaa authorization network default local ! aaa common-criteria policy Profil_pass min-length 8 max-length 64 numeric-count 1 upper-case 1 lower-case 1 special-case 1\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":322,"url":"https:\/\/www.safekom.pl\/blog\/palo-alto\/palo-ad-2012-user-maping\/","url_meta":{"origin":840,"position":4},"title":"Palo &#8211; AD 2012 user maping","author":"Micha\u0142 Iwa\u0144czuk","date":"20.09.2015","format":false,"excerpt":"Poni\u017cej opis jak pod\u0142\u0105czy\u0107 Palo do AD 2012 w celu pozyskania u\u017cytkownik\u00f3w do Autoryzacji SSH, WEB GUI. Kontroler domeny windows 2012r poziom AD 2012 AD01- 192.168.1.199 User-\u00a0pa-admin-user domena- safekom.pl Konfiguracja Palo: Device --> Server Profiles --> LDAP Gdzie w servers podajemy namiary na kontrolery domeny, w mym przypadku jest to\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":647,"url":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","url_meta":{"origin":840,"position":5},"title":"LAB &#8211;  IPSec Palo &#8211; Cisco ASA","author":"Micha\u0142 Iwa\u0144czuk","date":"23.03.2016","format":false,"excerpt":"Poni\u017cej pokazuj\u0119 jak zestawia\u0107 po\u0142\u0105czenie IPsec pomi\u0119dzy PaloAlto Networks a Cisco ASA. W mym przypadku oba urz\u0105dzenia s\u0105 w wersji wirtualnej ale konfiguracja ich odpowiada tak jak by\u015bmy konfigurowali urz\u0105dzenia fizyczne. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 86400s Faza 2 aes256 sha-1 pfs g2 28800s Palo Cisco ASA Sieci\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/comments?post=840"}],"version-history":[{"count":0,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/840\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media\/304"}],"wp:attachment":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media?parent=840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/categories?post=840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/tags?post=840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}