ISE Policy

Project Summary

Field Value

PRJ ID

PRJ-SPOKE-002

Owner

Evan Rosado

Priority

P1 (High)

Status

Active

Repository

~/atelier/_bibliotheca/domus-ise-ops

Antora Component

ise-ops

Antora Title

ISE Operations

Category

Network Security

2026 Commits

20

Site URL

docs.domusdigitalis.dev/ise-ops/

Purpose

The ISE Operations component documents Cisco ISE cluster administration, policy design, profiling, and deployment patterns. Unlike the platform-specific spokes (ise-linux, ise-windows), this repo covers ISE itself: authentication policies, authorization rules, profiling configuration, deployment topology, and integration with external systems.

It uses a multi-module Antora structure (authentication, profiling, policy, deployment, integration) to organize content by ISE functional area.

Scope

In Scope

  • ISE authentication policy design (802.1X, MAB, TACACS+)

  • ISE authorization rules and profiles

  • Endpoint profiling and identity groups

  • ISE deployment topology (PAN, PSN, MnT personas)

  • ISE-to-Active Directory integration

  • ISE-to-Vault PKI trust chain

  • Wireless 802.1X (WLC integration)

  • iPSK Manager HA configuration

  • ISE patch and upgrade procedures

  • Cross-references to platform spokes (ise-linux, ise-windows)

Out of Scope

  • Linux supplicant configuration (covered by ise-linux)

  • Windows supplicant configuration (covered by ise-windows)

  • ISE API automation (covered by netapi)

Status

Indicator Detail

Activity Level

Active — 20 commits, steady growth

Maturity

Early Production — multi-module structure established

Last Activity

2026

Key Milestone

Multi-module Antora nav (authentication, profiling, policy, deployment, integration)

Deployment Status

ISE 3.4 cluster documented, policies validated in home lab

Metadata

Field Value

PRJ ID

PRJ-SPOKE-002

Author

Evan Rosado

Date Created

2026-03-30

Last Updated

2026-03-30

Status

Active

Next Review

2026-04-15