View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

SEC0222 - ISE 2.0 pxGrid with ASA Firepower (Part 1)

Average: 5 (1 vote)
Difficulty Level: 
Lab Document: 
<Please login to see the content>
Video Download: 
Title: SEC0222 - Video Download $17.00
Purchase SEC0222 - Video Download $17.00
The video shows a functional integration of ASA Firepower with ISE 2.0 pxGrid service. We will have the Firepower join pxGrid using certificate-based authentication and subscribe for user contextual information. We will create and test Firepower access policies to restrict user traffic based on their AD group membership and assigned Security Group Tag. 
Part 1 of this video covers pxGrid configuration and certificate generation on ISE
  • pxGrid Certificate Generation (ISE and Firepower)
  • ISE pxGrid Configuration
  • Firepower Identity Policy
  • Firepower Access Control Policy
  • Security Group Tag (SGT)
  • SGT Exchange Protocol (SXP)

About Author

Metha Cheiwanichakorn, CCIE#23585 (RS, Sec, SP), is a Cisco networking enthusiast with years of experience in the industry. He is currently working as a consulting engineer for a Cisco partner. As a founder of and an instructor at, Metha enjoys learning and challenges himself with new Cisco technologies.


HI i have four nodes deployment , two admin/monitor and two PSNs , i have enabled the PIX grid on both the PSNs , but when i navigate to PixGrid service i find no nodes there with a note below the page saying "No connectivity to pxGrid node" , also when i try to go to setting and enable automatic approve new account , i get the below error message
"Failed to update Grid settings on the server"
any ideas

There are a few thing you can check/try.

1. Make sure you have PLUS license installed

2. Disable pxGrid, restart server and re-enable pxGrid.

3. Import pxGrid1 cert to Primary AM, and pxGrid2 cert to Sec AM as trusted cert.

4. Apply latest Patch

5. Search for ISE bugs

Thanks , i will try and feedback

It worked , but it needed to be activated on the Admin node

Strange. Cisco recommends having pxGrid controller runs on PSN but it that works for you, that should be ok.

Hi but now the status of the Pxgrid client is offline
any ideas

Can you go through troubleshooting step in the earlier post? 

Lab Minutes Classifieds


Vote for the Next Video Series
SD-Access (DNA)
SD-WAN (Viptela)
Network Programability
Total votes: 33