cisco-ise-mcp
Provides integration with Cisco Identity Services Engine (ISE) to query endpoint info, authentication logs, active sessions, policy context, and manage endpoints.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cisco-ise-mcpwhat's the status of MAC 00:1A:2B:3C:4D:5E?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cisco-ise-mcp
An MCP (Model Context Protocol) server for Cisco Identity Services Engine (ISE) 3.2, exposing ISE ERS and MNT APIs as MCP tools. It runs locally (stdio), in Docker, and as a Cloud Foundry application, with ISE credential passthrough as the primary authentication model.
Scope (and deliberate non-scope)
This server focuses on identity, endpoints, sessions, authentication, policy, profiling, and authorization context from ISE. It intentionally does not try to duplicate topology or device discovery — those belong to Catalyst Center, Arista CVaaS, NetBox, and similar source-of-truth MCP servers. It is designed to be one sub-agent that a future orchestrator combines with:
Cisco Catalyst Center MCP
Arista CVaaS MCP
NetBox / other network MCPs
Related MCP server: cisco-secure-access-mcp
Primary use cases
Query endpoint info by MAC, IP, hostname, username, or endpoint ID.
Query authentication/session logs for a MAC.
Query active session info for a MAC or IP.
Query policy/context associated with a MAC.
Aggregate ISE context for a MAC (endpoint group, profile, identity group, SGT/SGACL, authorization profile, auth status, recent RADIUS failures, MNT data where available).
Produce NOC/incident-style summaries.
Act as an ISE identity/policy sub-agent for orchestration.
Run centrally on Cloud Foundry for Copilot Studio, Teams, and direct MCP clients.
Architecture
MCP client ──HTTP(S)──> [cisco-ise-mcp]
├── auth/ passthrough | service_account (pluggable)
├── tools/ endpoint, session, policy, sgt, identity, write
├── ise/ client (async httpx) → ERS + MNT
└── audit/redaction/validation
│
▼
Cisco ISE 3.2 deployment VIP (ERS :443 /ers, MNT /admin/API/mnt)See docs/architecture.md.
Authentication (two independent concepts)
Client → MCP server: the client authenticates with ISE credentials; the server validates them against ISE and issues a random MCP session id. Subsequent calls present that id in the
X-MCP-Sessionheader (orAuthorization: Bearer <id>).MCP server → ISE: in
passthroughthe server uses the authenticated user's ISE credential context; inservice_accountit uses configured ISE service-account creds.
Modes: ISE_AUTH_MODE=passthrough (default) | service_account. Reserved for later:
api_key, entra_oidc, jwt, reverse_proxy_header, mtls (interface is pluggable —
adding one does not touch tool logic). Full detail: docs/authentication.md.
Sessions are memory-only in v1 (lost on restart); TTL and idle timeout are configurable. Credentials are never written to disk, never logged, never returned.
Read-only vs read/write
ISE_MCP_MODE=readonly (default) | readwrite. Write tools (ise_create_endpoint,
ise_assign_endpoint_group, ise_delete_endpoint) are gated by this flag; delete
additionally requires ISE_ENABLE_DANGEROUS_TOOLS=true. ISE still enforces the caller's
own permissions server-side.
Quick start (local)
uv venv && source .venv/bin/activate # or: python -m venv .venv && source .venv/bin/activate
uv pip install -e ".[dev]" # or: pip install -e ".[dev]"
cp .env.example .env # edit; .env is gitignored
python -m cisco_ise_mcp # honors MCP_TRANSPORT (streamable-http default)For stdio (single-user local MCP client), set MCP_TRANSPORT=stdio and use
ISE_AUTH_MODE=service_account (stdio has no place to carry a session header).
Tests
pytestDocker
cp .env.example .env
docker compose up --build
# server on http://localhost:8005 ; health at /healthzCloud Foundry
Target: ORG <your-org> / SPACE <your-space>. Two apps: cisco-ise-mcp-ro and cisco-ise-mcp-rw.
Only sample manifests are committed. Real manifests (manifest.yml, manifest-ro.yml,
manifest-rw.yml) are gitignored because they carry environment-specific values:
cp manifest-ro.sample.yml manifest-ro.yml # then edit routes/env for your space
cf push -f manifest-ro.ymlSecrets must come from your approved pipeline/secret mechanism into CF env vars — never
commit them into manifests or VCAP. The external route (cisco-ise-mcp.example.com)
is fronted by F5 later; nothing in this repo assumes F5 details. See
docs/cloud-foundry.md.
MCP tools
Full reference: docs/mcp-tools.md. Summary:
Group | Tools |
Health/auth |
|
Endpoint |
|
Session/auth |
|
Policy/context |
|
Identity |
|
TrustSec |
|
Network device |
|
Write (gated) |
|
Security
See SECURITY.md and docs/ise-permissions.md. No real secrets live in this repo; all examples are obvious placeholders.
License
MIT — see LICENSE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-quality-maintenanceEnables management of Cisco Identity Services Engine (ISE) resources through the ERS API. Supports identity management, endpoint registration, network device configuration, and authorization profiles through natural language interactions.
- AlicenseAqualityCmaintenanceA community MCP server for Cisco Secure Access that exposes the Secure Access REST API to AI clients as a curated catalog of tools for Admin, Deployments, Investigate, Policies, and Reports.421Apache 2.0
- Flicense-qualityDmaintenanceEnables MCP clients to interact with Palo Alto Networks firewalls and Panorama, providing tools to retrieve address objects, security zones, policies, and system information.12
- Alicense-qualityCmaintenanceExposes the LogicMonitor REST API as MCP tools with per-request LMv1 authentication, enabling querying of devices, alerts, reports, and more.Apache 2.0
Related MCP Connectors
Search, document and execute authenticated API calls across 500+ apps via one MCP server
34 production API tools over one hosted MCP endpoint.
SecurityTrails MCP — wraps SecurityTrails API (securitytrails.com)
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/dlhace/cisco-ise-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server