<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No problem about the delayed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972569#M38286</link>
    <description>&lt;P&gt;No problem about the delayed reply. To answer your questions:&lt;/P&gt;
&lt;P&gt;1. Yes, you can create a new VLAN with a new subnet that is different than your current one&lt;/P&gt;
&lt;P&gt;2. If your switch is Layer 3 capable then you should be able to create an SVI for that VLAN to provide default-gateway/routing&lt;/P&gt;
&lt;P&gt;3. You can then create an ACL and attach it to the SVI to restrict access&lt;/P&gt;
&lt;P&gt;Does this make sense?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 17:05:38 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2016-10-25T17:05:38Z</dc:date>
    <item>
      <title>ISE test environment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972565#M38282</link>
      <description>&lt;P&gt;I am attempting to create an ISE lab at home. &amp;nbsp;But I wanted to access the ISE interface from my production network, but at the same time segregate the ISE virtual machine and switches in there own environment. &amp;nbsp;So I was thinking I could create another VLAN, and put all the ISE test stuff in that VLAN.&lt;/P&gt;
&lt;P&gt;But I am a little confused on how to get the routing working between the two environments, and if it's even possible to keep the ISE console in my production network too.&lt;/P&gt;
&lt;P&gt;I have the ISE virtual machine running on an ESXi server. &amp;nbsp;So I created another vSwitch and ran a dedicated cable to the production switch. &amp;nbsp;I created the second VLAN and added both VLANs to that switchport. &amp;nbsp;But I can no longer hit ISE. &amp;nbsp;I'm wondering maybe it was the VLAN setup in the ISE initial setup that has to be changed.&lt;/P&gt;
&lt;P&gt;What would be the best way to setup this ISE test environment?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972565#M38282</guid>
      <dc:creator>Evan Ray</dc:creator>
      <dc:date>2019-03-11T07:05:13Z</dc:date>
    </item>
    <item>
      <title>Any thoughts on this?  There</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972566#M38283</link>
      <description>&lt;P&gt;Any thoughts on this? &amp;nbsp;There has to be others working and labbing with ISE in a similar manner.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2016 07:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972566#M38283</guid>
      <dc:creator>Evan Ray</dc:creator>
      <dc:date>2016-10-01T07:44:10Z</dc:date>
    </item>
    <item>
      <title>hello Evan-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972567#M38284</link>
      <description>&lt;P&gt;hello Evan-&lt;/P&gt;
&lt;P&gt;- What you described here should work fine&lt;/P&gt;
&lt;P&gt;- There shouldn't be any VLAN related settings in ISE&lt;/P&gt;
&lt;P&gt;- Do you have an SVI created for the new VLAN that is required for routing&lt;/P&gt;
&lt;P&gt;- Is the SVI on the same switch? If not, is the new VLAN allowed on the trunk links connecting the switches&lt;/P&gt;
&lt;P&gt;- It would probably be helpful if you post a diagram of your setup&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 01:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972567#M38284</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-03T01:51:22Z</dc:date>
    </item>
    <item>
      <title>I do not have a specified SVI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972568#M38285</link>
      <description>&lt;P&gt;I do not have a specified SVI for the new VLAN that ISE will reside in. &amp;nbsp;So everything resides on the same switch, does that mean I could create a VLAN and specify an SVI and assign 6 ports to that VLAN, all on the same switch? &amp;nbsp;That would work?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My concern for this lab, is that it has it's own Active Directory server, and soon it's own firewall. &amp;nbsp;So I wanted to keep it separate, but I also want to be able to manage it from my workstation on the production network. &amp;nbsp;I'm starting to see that SVI's are my saving grace.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry for the late reply, and thanks for responding and helping Neno!&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 09:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972568#M38285</guid>
      <dc:creator>Evan Ray</dc:creator>
      <dc:date>2016-10-22T09:15:29Z</dc:date>
    </item>
    <item>
      <title>No problem about the delayed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972569#M38286</link>
      <description>&lt;P&gt;No problem about the delayed reply. To answer your questions:&lt;/P&gt;
&lt;P&gt;1. Yes, you can create a new VLAN with a new subnet that is different than your current one&lt;/P&gt;
&lt;P&gt;2. If your switch is Layer 3 capable then you should be able to create an SVI for that VLAN to provide default-gateway/routing&lt;/P&gt;
&lt;P&gt;3. You can then create an ACL and attach it to the SVI to restrict access&lt;/P&gt;
&lt;P&gt;Does this make sense?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 17:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972569#M38286</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-25T17:05:38Z</dc:date>
    </item>
    <item>
      <title>So I was able to configure an</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972570#M38287</link>
      <description>&lt;P&gt;So I was able to configure an SVI on my switch, which is a 2960. &amp;nbsp;At first I thought I had to upgrade the code to IOS version 12.2(55)SE to support the 'ip routing' command, but I think I'm okay.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Currently my test environment doesn't have an ASA in it. &amp;nbsp;I have it powered up and ready, I just have to upgrade the code and get it connected.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the help Neno! &amp;nbsp;This definitely did help and make total sense!!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 21:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972570#M38287</guid>
      <dc:creator>Evan Ray</dc:creator>
      <dc:date>2016-10-29T21:05:40Z</dc:date>
    </item>
    <item>
      <title>No problem! Glad I was able</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972571#M38288</link>
      <description>&lt;P&gt;No problem! Glad I was able to help!&lt;/P&gt;
&lt;P&gt;Now, if your issue is resolved, you should mark the thread as "answered" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Oct 2016 15:59:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-test-environment/m-p/2972571#M38288</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-30T15:59:33Z</dc:date>
    </item>
  </channel>
</rss>

