<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A few questions about a Cisco/3rd party WAN setup in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539689#M500234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.A. No data available presently for such limit. I do expect 20 would work.&lt;/P&gt;&lt;P&gt;Regarding the incomplete section, please cite the section and paragraph or go ahead and log a doc bug.&lt;/P&gt;&lt;P&gt;1.B. By specifying ISE as the IP helper address at an SVI of a particular subnet, then ISE should be able to return a DHCP assignment for that subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If the NAD not supporting URL redirection, we may either specify a friendly FQDN for an ISE client provisioning portal or use the Call Home setting in ISE Posture profile or use the Auth VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2018 04:23:37 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-05-09T04:23:37Z</dc:date>
    <item>
      <title>A few questions about a Cisco/3rd party WAN setup</title>
      <link>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539688#M500233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a partner that has successfully done a test on deployment ISE at a regional hub with posture happening on 3rd party at the branches, however, we have a few questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) A) In the link below, for DHCP/DNS fencing, is there a limit on the number of subnets that can be configured. Say 20,50,100?&lt;BR /&gt;ALso, there is a incomplete section - (For more information, see ),&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01001.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01001.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01001.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; B). Does the IP-Helper allow ISE to selectively provide the correct DHCP for that branch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Since some of the switches do not support URL redirection for posture, the partner statically entered an IP address in the anyconnect profile on ISE.&amp;nbsp; Is that going to cause issues with teh DHCP/DNS method and session ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 13:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539688#M500233</guid>
      <dc:creator>tisnow</dc:creator>
      <dc:date>2018-05-08T13:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions about a Cisco/3rd party WAN setup</title>
      <link>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539689#M500234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.A. No data available presently for such limit. I do expect 20 would work.&lt;/P&gt;&lt;P&gt;Regarding the incomplete section, please cite the section and paragraph or go ahead and log a doc bug.&lt;/P&gt;&lt;P&gt;1.B. By specifying ISE as the IP helper address at an SVI of a particular subnet, then ISE should be able to return a DHCP assignment for that subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If the NAD not supporting URL redirection, we may either specify a friendly FQDN for an ISE client provisioning portal or use the Call Home setting in ISE Posture profile or use the Auth VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 04:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539689#M500234</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-09T04:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions about a Cisco/3rd party WAN setup</title>
      <link>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539690#M500238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1A)&amp;nbsp; Could we confirm 100 would work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1B)&amp;nbsp; The documentation bug is here -&lt;/P&gt;&lt;H3 class="sectiontitle"&gt;URL Redirect Mechanism and Auth VLAN&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; Is there a guide on when to use each?&amp;nbsp; We hardcoded the discovery address but I recall have session linkage issues in the past.&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Auth Vlan - would be for the DHCP/DNS inline type solution,&amp;nbsp; does that allow ISe to respond on behalf of itself with teh discovery address?&amp;nbsp; Is there a flow diagram (I may have missed it)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Hsing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 04:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539690#M500238</guid>
      <dc:creator>tisnow</dc:creator>
      <dc:date>2018-05-09T04:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: A few questions about a Cisco/3rd party WAN setup</title>
      <link>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539691#M500243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1A. Sorry. No data to confirm whether 100 works.&lt;/P&gt;&lt;P&gt;1B. CDETS ID?&lt;/P&gt;&lt;P&gt;2. Client Provisioning Portal FQDN and Call Home setting are covered in &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-76354"&gt;[ISE Lab Guide] ISE 2.2 Update&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200604-Configure-Third-Party-NAD-Redirection-on.html"&gt;Configure Third-Party NAD Redirection on ISE 2.1 - Cisco&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; on Auth VLAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2018 22:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/a-few-questions-about-a-cisco-3rd-party-wan-setup/m-p/3539691#M500243</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-10T22:47:10Z</dc:date>
    </item>
  </channel>
</rss>

