<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bug ID CSCve08815 raised to in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052644#M23783</link>
    <description>&lt;P&gt;Bug ID&amp;nbsp;CSCve08815 raised to track the issue. No fix available yet.&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2017 11:14:46 GMT</pubDate>
    <dc:creator>Andreas di Zazzo</dc:creator>
    <dc:date>2017-05-03T11:14:46Z</dc:date>
    <item>
      <title>Docker0 interface in ISE 2.2 causing problem</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052641#M23780</link>
      <description>&lt;P&gt;Upgraded a customer’s ISE to 2.2 yesterday and we ran into a real surprise. After the upgrade the first ISE node to 2.2 it started complaining it couldn’t reach DNS servers and other services. We had previously upgraded their ISE lab without any problems. Couldn’t figure out why production environment did this until we did some tracing from ISE CLI and realized the IP packets never left the box.&lt;/P&gt;
&lt;P&gt;A quick look in the ISE routing table revealed a brand new interface (new in ISE 2.2) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;customer-ise2.2-node/admin# sh int&lt;/P&gt;
&lt;P&gt;docker0: flags=4099&amp;lt;UP,BROADCAST,MULTICAST&amp;gt;&amp;nbsp; mtu 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background: yellow;"&gt;inet 172.17.0.1&amp;nbsp; netmask 255.255.0.0&lt;/SPAN&gt;&amp;nbsp; broadcast 0.0.0.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ether 02:42:95:d3:20:9c&amp;nbsp; txqueuelen 0&amp;nbsp; (Ethernet)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 0&amp;nbsp; bytes 0 (0.0 B)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 0&amp;nbsp; bytes 0 (0.0 B)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GigabitEthernet 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;&amp;nbsp; mtu 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 172.26.50.99&amp;nbsp; netmask 255.255.255.0&amp;nbsp; broadcast 172.26.50.255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::20c:29ff:fea3:2de6&amp;nbsp; prefixlen 64&amp;nbsp; scopeid 0x20&amp;lt;link&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ether 00:0c:29:a3:2d:e6&amp;nbsp; txqueuelen 1000&amp;nbsp; (Ethernet)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 199152&amp;nbsp; bytes 86053852 (82.0 MiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 199707&amp;nbsp; bytes 124938725 (119.1 MiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GigabitEthernet 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;&amp;nbsp; mtu 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::20c:29ff:fea3:2df0&amp;nbsp; prefixlen 64&amp;nbsp; scopeid 0x20&amp;lt;link&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ether 00:0c:29:a3:2d:f0&amp;nbsp; txqueuelen 1000&amp;nbsp; (Ethernet)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 1959&amp;nbsp; bytes 184239 (179.9 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 16&amp;nbsp; bytes 1296 (1.2 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GigabitEthernet 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;&amp;nbsp; mtu 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::20c:29ff:fea3:2dfa&amp;nbsp; prefixlen 64&amp;nbsp; scopeid 0x20&amp;lt;link&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ether 00:0c:29:a3:2d:fa&amp;nbsp; txqueuelen 1000&amp;nbsp; (Ethernet)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 1960&amp;nbsp; bytes 184299 (179.9 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 16&amp;nbsp; bytes 1296 (1.2 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GigabitEthernet 3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;&amp;nbsp; mtu 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 fe80::20c:29ff:fea3:2d04&amp;nbsp; prefixlen 64&amp;nbsp; scopeid 0x20&amp;lt;link&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ether 00:0c:29:a3:2d:04&amp;nbsp; txqueuelen 1000&amp;nbsp; (Ethernet)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 1960&amp;nbsp; bytes 184299 (179.9 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 16&amp;nbsp; bytes 1296 (1.2 KiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lo: flags=73&amp;lt;UP,LOOPBACK,RUNNING&amp;gt;&amp;nbsp; mtu 65536&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet 127.0.0.1&amp;nbsp; netmask 255.0.0.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 ::1&amp;nbsp; prefixlen 128&amp;nbsp; scopeid 0x10&amp;lt;host&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; loop&amp;nbsp; txqueuelen 0&amp;nbsp; (Local Loopback)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets 9695456&amp;nbsp; bytes 3782997962 (3.5 GiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX errors 0&amp;nbsp; dropped 0&amp;nbsp; overruns 0&amp;nbsp; frame 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets 9695456&amp;nbsp; bytes 3782997962 (3.5 GiB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX errors 0&amp;nbsp; dropped 0 overruns 0&amp;nbsp; carrier 0&amp;nbsp; collisions 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;customer-ise2.2-node/admin# sh ip ro&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gateway&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Iface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;default&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.26.50.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;172.26.50.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;172.17.0.0/16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; docker0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WHY ON EARTH do Cisco address this internal docker0 interface with 172.17.0.0/16 ?!? And !! this network address cannot be changed. There is no configuration for this in either CLI or GUI.&lt;/P&gt;
&lt;P&gt;My customer had their DNS servers within the 172.17.0.0/16 range which now litteraly got blackholed by this new awesome docker0 interface which is locally connected to the ISE node.&lt;/P&gt;
&lt;P&gt;A workaround (that does work) is to create two static routes in the ISE CLI, 172.17.0.0/17 and 172.17.128.0/17 and point to default-gw. But seriously should that really be needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So how come we did not see this in the lab? By a total coincidence the management of the ISE nodes in the lab was using the 172.17.0.0/16 range. The ISE upgrader must have realized this because it assigned a –different- /16 range to the docker0 interface in the lab to it wouldn’t collide with the management ip.&lt;/P&gt;
&lt;P&gt;Since we had no services at this range we did not notice this new behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why this docker0 interface cannot use the 127.0.0.0/8 range is beyond me because it seems to be for internal ISE communications only.&lt;/P&gt;
&lt;P&gt;Oh and no word about this is release notes or anywhere else for that matter. When upgrading the remaining nodes in the ISE 2.2 cluster, some of the other nodes picked different networks such as 172.18.0.0/16&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052641#M23780</guid>
      <dc:creator>Andreas di Zazzo</dc:creator>
      <dc:date>2019-03-11T07:29:42Z</dc:date>
    </item>
    <item>
      <title>Hi Andreas, Hi All,</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052642#M23781</link>
      <description>&lt;P&gt;Hi Andreas, Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;experiencing the same issues about docker network selection. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My client is running it's identity stores (AD/LDAP) in 172.18.0.0....&lt;/P&gt;
&lt;P&gt;I can confirm the workaround BEFORE upgrade.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;ISE02/dthoben# sh ip route&lt;/P&gt;
&lt;P&gt;Destination Gateway Iface&lt;BR /&gt;----------- ------- -----&lt;BR /&gt;default 172.17.122.254 eth0&lt;BR /&gt;172.17.122.0/23 0.0.0.0 eth0&lt;BR /&gt;&lt;STRONG&gt;172.18.0.0/17 172.17.129.254 eth0 (static route)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;172.18.128.0/17 172.17.129.254 eth0 (static route)&lt;/STRONG&gt;&lt;BR /&gt;172.18.0.0/16 0.0.0.0 docker0&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;David Thoben&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 17:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052642#M23781</guid>
      <dc:creator>David Thoben</dc:creator>
      <dc:date>2017-03-22T17:38:53Z</dc:date>
    </item>
    <item>
      <title>Update:</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052643#M23782</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;
&lt;P&gt;Just configure multiple interfaces to move the range of the docker interface multiple times (before upgrade).&lt;/P&gt;
&lt;P&gt;-OR-&lt;/P&gt;
&lt;P&gt;Configure a large subnet onto a single interface to move the docker interface to a proper position&amp;nbsp;(before upgrade).&lt;/P&gt;
&lt;P&gt;ISE02/dthoben# sh ip route&lt;/P&gt;
&lt;P&gt;Destination Gateway Iface&lt;BR /&gt;----------- ------- -----&lt;BR /&gt;default 172.17.144.254 eth0&lt;BR /&gt;172.17.144.0/24 0.0.0.0 eth0&lt;BR /&gt;172.18.144.0/24 0.0.0.0 eth1&lt;BR /&gt;172.19.144.0/24 0.0.0.0 eth3&lt;BR /&gt;172.20.144.0/24 0.0.0.0 eth2&lt;BR /&gt;172.21.0.0/16 0.0.0.0 docker0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;David Thoben&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 17:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052643#M23782</guid>
      <dc:creator>David Thoben</dc:creator>
      <dc:date>2017-03-22T17:39:38Z</dc:date>
    </item>
    <item>
      <title>Bug ID CSCve08815 raised to</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052644#M23783</link>
      <description>&lt;P&gt;Bug ID&amp;nbsp;CSCve08815 raised to track the issue. No fix available yet.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 11:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052644#M23783</guid>
      <dc:creator>Andreas di Zazzo</dc:creator>
      <dc:date>2017-05-03T11:14:46Z</dc:date>
    </item>
    <item>
      <title>I ran into this as well when</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052645#M23784</link>
      <description>&lt;P&gt;I ran into this as well when upgrading my dev ISE appliances. &amp;nbsp;The FTP repo that I use for backing up the ise appliances uses a 172.17 IP address and was broken by the 2.1 to 2.2 upgrade. &amp;nbsp;I added more specific routes via CLI to work around this. &amp;nbsp;However, when I went to upgrade my production appliances, I pre-added the specific routes, and the 2.2 upgrade failed on the secondary PAN with "500 internal error". &amp;nbsp;I removed the routes, and the 2.2 upgrade was then successful. &amp;nbsp;Once the upgrade of all nodes is successful, I will re-add the routes to all appliances. &amp;nbsp;I know this is a docker default, but hopefully Cisco can come with a fix to minimize the impact of this in the future.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 22:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052645#M23784</guid>
      <dc:creator>dgoodenberger</dc:creator>
      <dc:date>2017-05-19T22:17:46Z</dc:date>
    </item>
    <item>
      <title>Appears to be fixed as on 18</title>
      <link>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052646#M23785</link>
      <description>&lt;P&gt;Appears to be fixed as of 18 May 2017. &amp;nbsp;They have changed the docker route to use&amp;nbsp;&lt;SPAN&gt;169.254.0.0/24.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 23:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/docker0-interface-in-ise-2-2-causing-problem/m-p/3052646#M23785</guid>
      <dc:creator>dgoodenberger</dc:creator>
      <dc:date>2017-05-19T23:03:00Z</dc:date>
    </item>
  </channel>
</rss>

