<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic F5 ISE integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/f5-ise-integration/m-p/3860109#M472802</link>
    <description>&lt;P&gt;We have a customer who has F5 and PSNs in LTM mode but are doing an SNAT for incoming radius traffic hence all radius requests appear to come from the F5. This is because F5 and PSNs are separated by L3 and are not physically inline.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However it is always recommended to not have SNAT for incoming radius traffic.&lt;/P&gt;
&lt;P&gt;Is it possible to have F5 not be physically inline to the PSNs (F5 is not the default gateway of the PSNs) and still avoid SNAT for radius ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;F5 being physically inline to the PSNs as shown in the below guide has always worked for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159#toc-hId--500784889" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159#toc-hId--500784889&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2019 13:02:17 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2019-05-21T13:02:17Z</dc:date>
    <item>
      <title>F5 ISE integration</title>
      <link>https://community.cisco.com/t5/network-access-control/f5-ise-integration/m-p/3860109#M472802</link>
      <description>&lt;P&gt;We have a customer who has F5 and PSNs in LTM mode but are doing an SNAT for incoming radius traffic hence all radius requests appear to come from the F5. This is because F5 and PSNs are separated by L3 and are not physically inline.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However it is always recommended to not have SNAT for incoming radius traffic.&lt;/P&gt;
&lt;P&gt;Is it possible to have F5 not be physically inline to the PSNs (F5 is not the default gateway of the PSNs) and still avoid SNAT for radius ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;F5 being physically inline to the PSNs as shown in the below guide has always worked for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159#toc-hId--500784889" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159#toc-hId--500784889&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 13:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/f5-ise-integration/m-p/3860109#M472802</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2019-05-21T13:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ISE integration</title>
      <link>https://community.cisco.com/t5/network-access-control/f5-ise-integration/m-p/3884428#M472805</link>
      <description>&lt;P&gt;Yes, it is possible although does have some additional traffic engineering challenges.&amp;nbsp; More info in the F5-Cisco ISE Load Balancing Guide and in BRKSEC-3699 (Reference presentation) posted to CiscoLive.com.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 01:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/f5-ise-integration/m-p/3884428#M472805</guid>
      <dc:creator>chyps</dc:creator>
      <dc:date>2019-07-04T01:38:55Z</dc:date>
    </item>
  </channel>
</rss>

