Skip to content

Zero Trust & Network Access Control

Cisco ISE Design & Deployment

Every device on the network is identified, postured, and authorized before it gets an address.

The problem

A network that authorises by physical port cannot tell the difference between a corporate laptop, a contractor's personal machine, and something that was plugged into a conference room jack ten minutes ago. Most organisations know this and have not fixed it, because the fix means telling the network to start refusing things.

How we approach it

We design the Cisco ISE deployment around the device inventory you actually have rather than the one on the asset register — including everything that cannot run a supplicant. High availability and failure behaviour are designed up front, because the question "what happens to the network if ISE is unreachable" has to have a deliberate answer.

What the work covers

  • Greenfield architecture and high-availability design
  • Migration from legacy ACS / unmanaged access
  • Policy baselines for profiling, posture, remediation, enforcement
  • Integration with SCCM, ACAS, EPO, MDE