This article documents the initial setup of a Cisco Identity Services Engine (ISE) virtual machine, from configuring the node through the console to opening the dashboard for the first time. The lab uses Cisco ISE 3.5 Patch 0.
Lab environment#
| Parameter | Value |
|---|---|
| Platform | Cisco ISE VM |
| Version | Cisco ISE 3.5 Patch 0 |
| Hostname | ise121 |
| DNS domain | company.local |
| Management interface | GigabitEthernet 0 (default 0 accepted) |
| IPv4 address | 198.18.134.121 |
| Subnet mask | 255.255.192.0 |
| Default gateway | 198.18.128.1 |
| Primary DNS server | 198.18.134.50 |
| NTP servers | 0.id.pool.ntp.org, time.windows.com, time.google.com |
| Time zone | Asia/Jakarta |
| SSH | Enabled |
The IP, DNS, and NTP values above are specific to this lab. Use values that are appropriate for your network.
Prerequisites#
- Cisco ISE VM is installed and accessible through its console.
- Prepare a hostname, static IP address, subnet mask, gateway, DNS server, and reachable NTP servers.
- Have administrator credentials ready. The password is entered interactively and is not included in the article notes.
Cisco ISE uses an interactive setup program to configure the initial network settings and administrator credentials. Ensure that DNS and NTP are reachable during setup (Cisco ISE Installation Guide 3.5).
1. Configure the node through the console#
Follow the Cisco ISE setup prompts in the console. In this lab, the hostname and DNS domain are:
1Enter hostname[]: ise121
2Enter default DNS domain[]: company.localSelect the management interface. The prompt offers GigabitEthernet 0 as the default, and this lab accepts the default value 0. Then enter the IPv4 address, subnet mask, and gateway:
1Enter the number of the interface that must be configured as the management interface[0]:
2Enter IPv4/IPv6 address[]: 198.18.134.121
3Enter IP netmask[]: 255.255.192.0
4Enter IP default gateway[]: 198.18.128.1IPv6 is not configured. Enter the primary DNS server, then add the three NTP servers. Finally, set the time zone to Asia/Jakarta and enable SSH:
1Do you want to configure IPv6 address? Y/N [N]: n
2Enter primary nameserver[]: 198.18.134.50
3Add secondary nameserver? Y/N [N]: n
4Enter NTP server[time.nist.gov]: 0.id.pool.ntp.org
5Add another NTP server? Y/N [N]: y
6Enter additional NTP server[time.nist.gov]: time.windows.com
7Add another NTP server? Y/N [N]: y
8Enter additional NTP server[time.nist.gov]: time.google.com
9Enter system timezone[UTC]: Asia/Jakarta
10Enable SSH service? Y/N [N]: yUse the default username, admin. Set a password when prompted; password characters are not displayed in the console.
After setup applies the network configuration, the ISE processes start. The following capture shows the values entered through the console.

Figure 1. Hostname, management interface, IPv4, DNS, NTP, time zone, and SSH configuration.
2. Check ISE process status#
After setup completes, sign in to the CLI with the administrator account created during setup. Run this command to check the ISE processes:
1ise121/admin#show application status iseIn this lab session, several core processes were in the running state:
1Database Listener running
2Database Server running
3ISE Data Grid Service running
4Application Server running
5Profiler Database running
6ISE Elasticsearch runningThe session output also lists several additional services as disabled. Process status can depend on the node profile and enabled features, so check the services relevant to your deployment. Cisco also uses show application status ise as an installation verification step (Cisco ISE Installation Guide 3.5 — Verify the installation process).
3. Open the administration portal#
From a browser that can reach the Cisco ISE management IP address, open:
1https://198.18.134.121/admin/Sign in with the administrator username and password created during setup. This URL format and the initial credentials follow Cisco's login guide (Cisco ISE Installation Guide 3.5 — Log in to the web-based interface).
When the portal opened during this lab session, ISE displayed a notice that the Evaluation License was active and valid for 90 days.

Figure 2. The portal displays a 90-day evaluation license notice. The dashboard behind the dialog shows 88 days remaining in this capture.
The Evaluation License is enabled by default after Cisco ISE is installed. Cisco states that it is valid for 90 days and supports up to 100 endpoints (Cisco ISE Licensing Guide). The remaining days shown in the portal reflect when the capture was taken and may differ in another installation.
4. Review the initial dashboard#
After dismissing the license notice, the Cisco ISE dashboard opens. In this lab capture, the page shows the ise121 node, Evaluation Mode with 88 days remaining, and no endpoints recorded yet.

Figure 3. The initial dashboard after opening the administration portal.
Optional post-install password operations#
The terminal log also records two additional password operations. They are not required to complete the initial setup, but are included here to document the lab session.
Change the CLI password
The password command prompts for the current password, a new password, and confirmation. Password input is not shown in the log:
1ise121/admin#password
2Enter old password:
3Enter new password:
4Confirm new password:
5ise121/admin#Reset the Admin Portal account password
The log also records the following command and the response Password reset successfully.:
1ise121/admin#application reset-passwd ise admin
2Enter new password:
3Confirm new password:
4
5Password reset successfully.
6ise121/admin#According to the Cisco CLI Reference Guide, application reset-passwd resets the password for an Admin Portal account that has been locked after too many failed login attempts. This is an account recovery step, not a routine part of the initial setup (Cisco ISE CLI Reference Guide 3.5 — application reset-passwd).
Conclusion#
The Cisco ISE 3.5 Patch 0 node was configured through the console, its application processes were checked, and the Admin Portal and initial dashboard were accessed. The Evaluation License state described above reflects this lab session. Policy configuration, adding network devices, and onboarding endpoints are outside the scope of this guide.