<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-2-node-deployment/m-p/3064786#M24028</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Using DNS could be a solution. However, the wlc will send the request to 1 ISE and the customer will be redirect on the portal based on fqdn. If you're using round robin you can face an issue: I mean you can be redirected to 1 use while the session is on the 2nd one. In that case, users won't be able to get the portal and authenticate.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can found some free load balancer on Linux to achieve that goal.&lt;/P&gt;
&lt;P&gt;There is also another solution by using anycast capabilities on the routing side.&lt;/P&gt;
&lt;P&gt;There is good blog done (I won't re-explain all as it is well described):&amp;nbsp;http://www.networkworld.com/article/3074954/security/how-to-use-anycast-to-provide-high-availability-to-a-radius-server.html&lt;/P&gt;
&lt;P&gt;In same cases and based on customer environment I'm using 1 of the other solution.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 02:08:57 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2017-02-13T02:08:57Z</dc:date>
    <item>
      <title>Cisco ISE Guest 2 node deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-2-node-deployment/m-p/3064785#M24027</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I want to run guest services with 2 node deployment of ISE 2.1.&lt;/P&gt;
&lt;P&gt;We don't have load balancer for getting a VIP for the ise&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;what are the options we do can so we have a high availability of the guest services?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Scenario 1:-&lt;/P&gt;
&lt;P&gt;I have read blogs about deploying 2 portal pages redirecting based on the host name of the ISE where the request comes&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Scenario &lt;/SPAN&gt;2:-&lt;/P&gt;
&lt;P&gt;the ip host command as per documentation "When Cisco ISE processes an authorization profile redirect URL, it replaces the IP address with the FQDN of the Cisco ISE node." --&amp;gt; will this work with google/public dns servers?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;also if i make a entry on ise like below will&amp;nbsp;this work?&lt;/P&gt;
&lt;P&gt;ise1 :-&amp;nbsp;ip host 10.10.10.1 guestsevice guestservice.cisco.com&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ise2 :-&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip host 10.10.10.2&amp;nbsp;guestsevice guestservice.cisco.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;even will we need to different authorization rules and guest portal or one authorization &amp;amp; guest portal can do the work?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Need the best solution?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-2-node-deployment/m-p/3064785#M24027</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2019-03-11T07:27:18Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-2-node-deployment/m-p/3064786#M24028</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Using DNS could be a solution. However, the wlc will send the request to 1 ISE and the customer will be redirect on the portal based on fqdn. If you're using round robin you can face an issue: I mean you can be redirected to 1 use while the session is on the 2nd one. In that case, users won't be able to get the portal and authenticate.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can found some free load balancer on Linux to achieve that goal.&lt;/P&gt;
&lt;P&gt;There is also another solution by using anycast capabilities on the routing side.&lt;/P&gt;
&lt;P&gt;There is good blog done (I won't re-explain all as it is well described):&amp;nbsp;http://www.networkworld.com/article/3074954/security/how-to-use-anycast-to-provide-high-availability-to-a-radius-server.html&lt;/P&gt;
&lt;P&gt;In same cases and based on customer environment I'm using 1 of the other solution.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 02:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-2-node-deployment/m-p/3064786#M24028</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-02-13T02:08:57Z</dc:date>
    </item>
  </channel>
</rss>

