<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSNs with 2 interfaces for guest authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3681674#M495734</link>
    <description>&lt;P&gt;See also&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/psns-with-2-interfaces-for-guest-authentication/m-p/3679445" target="_blank"&gt;PSNs with 2 interfaces for guest authen...&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN&gt;by &lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-common-widget-user-name"&gt;&lt;SPAN class=""&gt;&lt;A id="link_19611c56d9c0ca" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/310855" target="_self"&gt;umahar&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;on 08-01-2018 11:41 AM)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Aug 2018 03:23:42 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-08-06T03:23:42Z</dc:date>
    <item>
      <title>PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3678607#M495729</link>
      <description>&lt;P&gt;We have an ISE Guest cluster with PSNs having 2 interfaces.&lt;/P&gt;
&lt;P&gt;One interface receives the radius request and the other interface receives the web redirected traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WLC----internal-network-----PSN---------------router&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During failover testing we shut down the router interface.&lt;/P&gt;
&lt;P&gt;WLC was still sending radius request to the internal-network interface of PSN because it was still alive. Endpoints when getting redirected to the other interface of the PSN are getting dropped.&lt;/P&gt;
&lt;P&gt;Is there a way for PSN to start dropping radius request on one interface if the second interface goes down ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3678607#M495729</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2020-02-21T19:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3678771#M495730</link>
      <description>Hi Umahar&lt;BR /&gt;&lt;BR /&gt;I'm sorry but what's your question?&lt;BR /&gt;I thing you're missing a part of your post.</description>
      <pubDate>Wed, 01 Aug 2018 02:49:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3678771#M495730</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-08-01T02:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3679166#M495731</link>
      <description>oh ya, I thought my post was autosaved. Still getting used to the new interface &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Wed, 01 Aug 2018 13:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3679166#M495731</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-08-01T13:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3679554#M495732</link>
      <description>&lt;P&gt;Unfortunately there's no tracking feature to do so and that's why I always implement ISE with multiple interfaces but use anycast design. As you can't shutdown the interface because tracking isn't there and you don't have access to linux shell, radius packets still go through the default ISE interface and it will redirect endpoints to a anycast IP which means:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- if interface 2 is down on ISE node 1, the routing will redirect the user to the same IP located on ISE node 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you follow me here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise, for customers who have Load-balancers, they can achieve the same thing by returning LB VIP and LB will be in charge to redirect traffic to ISE node 1 or 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 22:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3679554#M495732</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-08-01T22:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3681673#M495733</link>
      <description>&lt;P&gt;See also&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/psns-with-2-interfaces-for-guest-authentication/m-p/3679445" target="_blank"&gt;PSNs with 2 interfaces for guest authen...&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN&gt;by &lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-common-widget-user-name"&gt;&lt;SPAN class=""&gt;&lt;A id="link_19611c56d9c0ca" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/310855" target="_self"&gt;umahar&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;on 08-01-2018 11:41 AM)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 03:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3681673#M495733</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-08-06T03:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs with 2 interfaces for guest authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3681674#M495734</link>
      <description>&lt;P&gt;See also&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/psns-with-2-interfaces-for-guest-authentication/m-p/3679445" target="_blank"&gt;PSNs with 2 interfaces for guest authen...&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN&gt;by &lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cisco-Employee lia-component-common-widget-user-name"&gt;&lt;SPAN class=""&gt;&lt;A id="link_19611c56d9c0ca" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/310855" target="_self"&gt;umahar&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;on 08-01-2018 11:41 AM)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 03:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-with-2-interfaces-for-guest-authentication/m-p/3681674#M495734</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-08-06T03:23:42Z</dc:date>
    </item>
  </channel>
</rss>

