<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMware VMXNET3 Adapter Remapping in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824271#M474575</link>
    <description>The threshold appears to be 4 - when I only had 4 configured they were in the correct order.</description>
    <pubDate>Fri, 22 Mar 2019 09:45:16 GMT</pubDate>
    <dc:creator>noisey_uk</dc:creator>
    <dc:date>2019-03-22T09:45:16Z</dc:date>
    <item>
      <title>VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823131#M474559</link>
      <description>&lt;P&gt;Cisco Identity Services Engine Installation Guide, Release 2.4 states that "If you choose VMXNET3, you might have to remap the ESXi adapter to synchronize it with the ISE adapter order."&lt;/P&gt;
&lt;P&gt;My design requires 6 x VMXNET3 adapters and they're out of the expected order, as warned by this statement.&lt;/P&gt;
&lt;P&gt;Does anyone have information on *how* to remap the ESXi adapter so that it realigns with the ISE adapter order?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As present, this is the mapping:&lt;/P&gt;
&lt;P&gt;VMware Network Adapter 1 &amp;gt; ISE GE0&lt;BR /&gt;VMware Network Adapter 5 &amp;gt; ISE GE1&lt;BR /&gt;VMware Network Adapter 2 &amp;gt; ISE GE2&lt;BR /&gt;VMware Network Adapter 6 &amp;gt; ISE GE3&lt;BR /&gt;VMware Network Adapter 3 &amp;gt; ISE GE4&lt;BR /&gt;VMware Network Adapter 4 &amp;gt; ISE GE5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whereas I'd like the more intuitive mapping:&lt;/P&gt;
&lt;P&gt;VMware Network Adapter 1 &amp;gt; ISE GE0&lt;BR /&gt;VMware Network Adapter 2 &amp;gt; ISE GE1&lt;BR /&gt;VMware Network Adapter 3 &amp;gt; ISE GE2&lt;BR /&gt;VMware Network Adapter 4 &amp;gt; ISE GE3&lt;BR /&gt;VMware Network Adapter 5 &amp;gt; ISE GE4&lt;BR /&gt;VMware Network Adapter 6 &amp;gt; ISE GE5&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 17:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823131#M474559</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-20T17:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823231#M474567</link>
      <description>&lt;P&gt;Good question. I am wondering why this even happens in the first place.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strange that it only happens when you cross over a certain count (three?). I would still continue using vmxnet3 but I agree if you need to do this gymnastics for 50 nodes then you might be annoyed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 20:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823231#M474567</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-03-20T20:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823325#M474571</link>
      <description>&lt;P&gt;I believe the threshold is 4 before renumbering occurs.&amp;nbsp; I would be curious what design needs 6 NICS.&amp;nbsp; In a 100+ installs I have never used more than 2.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 01:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3823325#M474571</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-21T01:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824271#M474575</link>
      <description>The threshold appears to be 4 - when I only had 4 configured they were in the correct order.</description>
      <pubDate>Fri, 22 Mar 2019 09:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824271#M474575</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-22T09:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824277#M474579</link>
      <description>Correct.&lt;BR /&gt;3 sets of 2 bonded NICs. bond0 for management; bond1 for internal; bond2 for DMZ guest services. Granted, the NIC bonding is arguably over-the-top/unnecessary given it's a virtual appliance so both member interfaces will be connected to the same vSwitch.</description>
      <pubDate>Fri, 22 Mar 2019 09:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824277#M474579</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-22T09:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824400#M474582</link>
      <description>Connecting your DMZ to a shared vSwitch for both management and internal networks? Quite risky.&lt;BR /&gt;&lt;BR /&gt;As for your predicament, I'm unsure if it's possible to fix this without TAC involvement if you truly need more than 4 VMXNET3 interfaces.&lt;BR /&gt;&lt;BR /&gt;Here are a few possible solutions. Maybe one can apply:&lt;BR /&gt;&lt;BR /&gt;1) Involve TAC, this is a supported configuration afterall.&lt;BR /&gt;&lt;BR /&gt;2) Seeing as this is on the same vSwitch, perhaps you can put management and internal VLANs on the same bond. That would mean you only have 4 interfaces to deal with. There may or may not be security concerns but that's up to your architecture and where you can place your controls.&lt;BR /&gt;&lt;BR /&gt;3) Is there any particular reason why either the DMZ, Management or Internal networks will need more than 1Gbps at a time from this server for any one of these bonds? E1000 is an emulation of a 1Gbps NIC, which should be fine for most ISE deployments. For a PSN node the worst case scenario is that the Internal bond is used for both inter-ISE server traffic and AAA traffic. I'm unsure how many transactions per second you're expecting to hit, but I imagine 1Gbps worth full-duplex is a stretch for a single node. If you're hitting those kinds of numbers then you really should have more PSNs in place. If your server is an Admin node, then you are very unlikely to need VMXNET3.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 22 Mar 2019 14:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824400#M474582</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2019-03-22T14:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824573#M474584</link>
      <description>&lt;P&gt;Segregating traffic using VLANs (including in a vSwitch) is common accepted practice in most environments. If it was a highly secure environment then I would agree... but I'd also be using a two tiered firewall with different vendors. Horses for courses.&lt;BR /&gt;&lt;BR /&gt;TAC involvement was useless. They sent me information on VMware Workstation and vSphere 5.0, using the Client. It's always a lucky dip whether you get a useful response in my experience and unfortunately this time I didn't.&lt;BR /&gt;&lt;BR /&gt;Unless I've missed something, it's not possible to subinterface an ISE bond. They're not a true bond anyway - they're active/passive.&lt;BR /&gt;&lt;BR /&gt;Standardising on VMXNET3 across all VMs. It also gives the best room for future growth. It's one of those annoying situations where vendor Best Practice clashes - VMware's is to use VMXNET3 unless mandated otherwise; Cisco says that E1000 should be used, but only to avoid the situation I've come across.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 19:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824573#M474584</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-22T19:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824575#M474586</link>
      <description />
      <pubDate>Mon, 25 Mar 2019 22:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824575#M474586</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-25T22:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824910#M474587</link>
      <description>&lt;P&gt;I was thinking more along the lines of making the bond a couple of vNICs with the same access VLAN, and configuring the gateway's subinterface as dedicated for ISE. The bond could then serve both management and internal networks on a single subnet. You would add your security controls at the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not ideal, but it may work for you.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 20:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3824910#M474587</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2019-03-23T20:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3825889#M474589</link>
      <description>In ISE CLI, show interfaces. This will list the MAC addresses used by GigabitEthernet0-5.&lt;BR /&gt;Go to vSphere [your VM] Summary &amp;gt; Hardware Configuration. This will list the MAC addresses used by NETWORK ADAPTER X. Bear in mind that internal VMware enumeration (which is used later) is 1 number less than what is displayed. e.g. NETWORK ADAPTER 1 is ethernet0 internally to VMware.&lt;BR /&gt;By cross-referencing the MAC addresses, you can map each ISE GigabitEthernetX to its current VMware NETWORK ADAPTER.&lt;BR /&gt;In vSphere, go to [your VM] &amp;gt; Edit &amp;gt; VM Options &amp;gt; Configuration Parameters &amp;gt; Edit Configuration and you will see the current mapping of VMware Network Adapter to PCI Slot Number:&lt;BR /&gt;ethernet0.pciSlotNumber 160 (ethernet0 = NETWORK ADAPTER 1)&lt;BR /&gt;ethernet1.pciSlotNumber 192 (ethernet1 = NETWORK ADAPTER 2)&lt;BR /&gt;ethernet2.pciSlotNumber 224 (ethernet2 = NETWORK ADAPTER 3)&lt;BR /&gt;ethernet3.pciSlotNumber 256 (ethernet3 = NETWORK ADAPTER 4)&lt;BR /&gt;ethernet4.pciSlotNumber 1184 (ethernet4 = NETWORK ADAPTER 5)&lt;BR /&gt;ethernet5.pciSlotNumber 1216 (ethernet5 = NETWORK ADAPTER 6)&lt;BR /&gt;Now, looking at this *from the perspective of the vSphere ESXi hypervisor*, reorder the interfaces.</description>
      <pubDate>Mon, 25 Mar 2019 22:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3825889#M474589</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-25T22:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: VMware VMXNET3 Adapter Remapping</title>
      <link>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3826269#M474591</link>
      <description>&lt;P&gt;If it works, awesome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you check that your mapping persists after you shutdown and power on the VM?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 13:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vmware-vmxnet3-adapter-remapping/m-p/3826269#M474591</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2019-03-26T13:42:25Z</dc:date>
    </item>
  </channel>
</rss>

