<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE with multiple Network interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278567#M149051</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For External Idenity sources Cisco ISE would use Eth0 as the default and only interface to communicate with them. But in case of exteranl RADIUS proxy request its not bounded to Eth0 interface and rather depends on the route on Cisco ISe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers the query&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Oct 2013 07:23:32 GMT</pubDate>
    <dc:creator>kmittal</dc:creator>
    <dc:date>2013-10-15T07:23:32Z</dc:date>
    <item>
      <title>Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278562#M148791</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am deploying Cisco ISE 1.2 in a distributed deployment and the requirement is to use external Radius proxy feature. ISE PSNs are designed to have 2 L3 NIC's, Eth0 for administration and Eth1 as client side facing NIC for Radius requests. I am interested to know would Cisco ISE in version 1.2 use Eth1 interface to send RADIUS&amp;nbsp; authentication request to external RADIUS Proxy server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could not find above information in &lt;SPAN style="font-size: 10pt;"&gt;Cisco SNS-3400 Series Appliance Ports Reference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.2/installation_guide/ise_app_c-ports.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/installation_guide/ise_app_c-ports.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278562#M148791</guid>
      <dc:creator>kmittal</dc:creator>
      <dc:date>2019-03-11T03:56:37Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278563#M148826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kumar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe you need to move the question to ACS/Identity and NAC section, it will be more accessible by the ISE experts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, ISE can support External RADIUS server as External Identity source, and this can be done though any interface like the Gig0 which is MGMT one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can consider your server like the AD as example, and the ISE will use Gig0 for traffic forwarding to any other parties used on the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_id_stores.html#wp1098609"&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_id_stores.html#wp1098609&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Ahmad.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Sep 2013 15:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278563#M148826</guid>
      <dc:creator>Ahmad Murad</dc:creator>
      <dc:date>2013-09-28T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278564#M148863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Ahmad for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ISE uses standard RADIUS authentication and authorization port to send request to Exteranl RADIUS proxy. As per the interface/port refrence guide of version 1.2 this is listed that is causing a confusion :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 712px;"&gt;&lt;TBODY&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="height: 15.0pt; width: 86pt;" width="114"&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD style="width: 143pt;" width="191"&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD style="width: 161pt;" width="215"&gt;Eth0&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;Eth1&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;Eth2&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;Eth3&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 96.0pt;"&gt;&lt;TD height="400" rowspan="2" style="height: 300.0pt;"&gt;Policy&amp;nbsp;&amp;nbsp; Service node&lt;/TD&gt;&lt;TD&gt;Session&lt;/TD&gt;&lt;TD align="left" colspan="4" height="128" style="height: 96.0pt; width: 305pt;" valign="top" width="407"&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="4" height="128" style="height: 96.0pt; width: 305pt;" width="407"&gt;&lt;BR /&gt; •UDP:1645, 1812 (RADIUS Authentication)&lt;BR /&gt; &lt;BR /&gt; •UDP:1646, 1813 (RADIUS Accounting)&lt;BR /&gt; &lt;BR /&gt; •UDP: 1700 (RADIUS change of authorization Send)&lt;BR /&gt; &lt;BR /&gt; •UDP: 1700, 3799 (RADIUS change of authorization Listen/Relay)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 204.0pt;"&gt;&lt;TD height="272" style="height: 204.0pt; width: 143pt;" width="191"&gt;External&amp;nbsp;&amp;nbsp; Identity Stores &lt;BR /&gt; and Resources&lt;/TD&gt;&lt;TD align="left" style="width: 161pt;" valign="top" width="215"&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD height="272" style="height: 204.0pt; width: 161pt;" width="215"&gt;&lt;BR /&gt; •TCP: 389, 3268, UDP: 389 (LDAP)&lt;BR /&gt; &lt;BR /&gt; •TCP: 445 (SMB)&lt;BR /&gt; &lt;BR /&gt; •TCP: 88, UDP: 88 (KDC)&lt;BR /&gt; &lt;BR /&gt; •TCP: 464 (KPASS)&lt;BR /&gt; &lt;BR /&gt; •UDP: 123 (NTP)&lt;BR /&gt; &lt;BR /&gt; •TCP: 53, UDP: 53 (DNS)&lt;BR /&gt; &lt;BR /&gt; (Admin user interface authentication and endpoint authentication)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In external Identity Stores and Resources it says Eth0 is used for &lt;SPAN style="font-size: 10pt;"&gt;(Admin user interface authentication and endpoint authentication), where under sessions it lists that all ports can be used for RADIUS Authentication and Authorization.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what I am missing to understand between the two if you can highlight that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Sep 2013 22:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278564#M148863</guid>
      <dc:creator>kmittal</dc:creator>
      <dc:date>2013-09-28T22:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278565#M148915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ahmed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did a TCP dump on eth1 interface and I could c the external radius proxy traffic being sent through Eth1 interface of ISE. It will put the complete setup and let you know the final results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 07:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278565#M148915</guid>
      <dc:creator>kmittal</dc:creator>
      <dc:date>2013-09-30T07:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278566#M148970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kumar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any update about your setup?&lt;/P&gt;&lt;P&gt;I'm asking because I need similar thing with different identity source and need to check if it is applicable or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Ahmad.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 13:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278566#M148970</guid>
      <dc:creator>Ahmad Murad</dc:creator>
      <dc:date>2013-10-03T13:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE with multiple Network interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278567#M149051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For External Idenity sources Cisco ISE would use Eth0 as the default and only interface to communicate with them. But in case of exteranl RADIUS proxy request its not bounded to Eth0 interface and rather depends on the route on Cisco ISe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers the query&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 07:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-with-multiple-network-interface/m-p/2278567#M149051</guid>
      <dc:creator>kmittal</dc:creator>
      <dc:date>2013-10-15T07:23:32Z</dc:date>
    </item>
  </channel>
</rss>

