<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Sponsor portal with load-balancer URL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780201#M486276</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you haven't already done so, please take a look at &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=ISE#/session/1511296160606001Af1J" target="_self"&gt;BRKSEC-3699&lt;/A&gt; which has a large section on PSN load balancing that also covers load balancing web services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 15:22:46 GMT</pubDate>
    <dc:creator>Timothy Abbott</dc:creator>
    <dc:date>2019-01-15T15:22:46Z</dc:date>
    <item>
      <title>ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780160#M486272</link>
      <description>&lt;P&gt;I have two ISE nodes running in Primary and Secondary mode, I have a sponsor portal established with a defined dns string internally for employees to reach, however we have a load-balancer(LB) managing the sponsor portals respectively.&amp;nbsp; When clients attempt to reach our sponsor portal they get caught by the LB which then presents a certificate error and won't redirect the client to the ISE nodes seamlessly.&amp;nbsp; On the ISE servers for the same portal we have valid external certs to prevent a cert error page from appearing.&amp;nbsp; Has anyone run a setup like this before?&amp;nbsp; I'll condense all the information I have below for ease of reading.&amp;nbsp; Also does the secondary even take any requests for sponsor logins?&amp;nbsp; Or is the primary the work horse?&amp;nbsp; I don't expect the portal to be heavily used but I could be wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the FQDN field filled out with my dns entry in ISE for the sponsor portal URL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The LB has the same FQDN defined for where to redirect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our internal DNS is pointing to our internal IP with the correct DNS entry.&amp;nbsp; Known because this works without the LB being active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The actual URL for ISE has a long string after the DNS name .com:8888/sponsorportal/...&lt;/P&gt;
&lt;P&gt;Should the full ISE URL be used on the LB or just the shortened FQDN?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 14:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780160#M486272</guid>
      <dc:creator>MP_Linc</dc:creator>
      <dc:date>2019-01-15T14:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780201#M486276</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you haven't already done so, please take a look at &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search.event=ciscoliveus2018&amp;amp;search=ISE#/session/1511296160606001Af1J" target="_self"&gt;BRKSEC-3699&lt;/A&gt; which has a large section on PSN load balancing that also covers load balancing web services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780201#M486276</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-01-15T15:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780295#M486288</link>
      <description>&lt;P&gt;For two nodes I wouldn't even bother load balancing the sponsor portal.&amp;nbsp; Create two A records in your DNS for the sponsor portal FQDN and put in the IPs of each of your ISE nodes.&amp;nbsp; Both ISE nodes can serve up the sponsor portal.&amp;nbsp; There is no concept of primary/secondary.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780295#M486288</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-01-15T16:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780479#M486295</link>
      <description>I wish I could have done it that way but the powers above me wanted it behind the LB adding the cert to the LB alleviated my original issue.  I do appreciate you answering the question about how the ISE nodes respond to requests for the portal.</description>
      <pubDate>Tue, 15 Jan 2019 19:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780479#M486295</guid>
      <dc:creator>MP_Linc</dc:creator>
      <dc:date>2019-01-15T19:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780582#M486299</link>
      <description>&lt;P&gt;What brand load balancer are you using? It sounds like you're doing ssl decryption when you should be able to just sticky/persist the session traffic and let ise handle it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 21:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3780582#M486299</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-15T21:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor portal with load-balancer URL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3781039#M486304</link>
      <description>Its a Citrix Netscaler, but the issue for the page not appearing appropriately was resolved by placing the cert on the LB.  I sadly only manage ISE and the network equipment so I usually work with another team for server related tasks.</description>
      <pubDate>Wed, 16 Jan 2019 12:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-with-load-balancer-url/m-p/3781039#M486304</guid>
      <dc:creator>MP_Linc</dc:creator>
      <dc:date>2019-01-16T12:06:42Z</dc:date>
    </item>
  </channel>
</rss>

