<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2 Max Sessions with distributed PSNs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505557#M517358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming same device used, then same user should be persisted to same PSN via Calling Station ID. As noted, there is a roadmap item.&amp;nbsp; Plan is to extend feature to node group/PSN cluster but details and timing need to be communicated privately by ISE PM team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Apr 2018 11:08:30 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-04-18T11:08:30Z</dc:date>
    <item>
      <title>ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505550#M517336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi TME team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just need to confirm if there are any caveats related to multiple PSNs and a load balancer with the new ISE 2.2 feature for Max Sessions.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this feature still work correctly if multiple user/endpoint sessions happen to be sent to different PSNs by the load balancer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 06:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505550#M517336</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-12T06:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505551#M517338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This feature is currently per PSN but not globally. Global limits are in road map.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505551#M517338</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-12T07:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505552#M517340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hsing for the quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe we can add a sticky rule in the F5 to send all sessions with the same RADIUS username to the same PSN.&lt;/P&gt;&lt;P&gt;Do you think that might be a valid workaround for the current limitation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505552#M517340</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-12T07:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505553#M517341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I believe your workaround should help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505553#M517341</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-12T07:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505554#M517347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/28477"&gt;chyps&lt;/A&gt;, I wanted to run this by you since you have prior experience from writing the how-to guide with F5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking about trying the following persistence logic in the F5 to work around this Max Session limitation in ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if framed-protocol, then use username as persistence identifier&lt;/P&gt;&lt;P&gt;if not framed-protocol, then use calling-station-id with fallback to nas-ip-address as persistence identifier&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think this is feasible to do with an iRule?&lt;/P&gt;&lt;P&gt;If so, do you foresee any issues with this persistence config for any ISE flows?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer is deploying wired/wireless dot1x and wireless Guest, but no BYOD or Posture flows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2018 00:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505554#M517347</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-14T00:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505555#M517353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since LB is not terminating the RADIUS session, I question if username will be available or consistent for Framed (802.1X) flows.&amp;nbsp; For PEAP, the inner identity is not exposed and what is exposed is outer identity.&amp;nbsp; For EAP-TLS, the username is often an logical extract from cert field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2018 04:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505555#M517353</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-04-17T04:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505556#M517355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig. You make a good point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like we might have to just change the persistence identifier to use the NAS-IP. It won't provide as much balancing as using the Calling-Station-ID, but it might be the best way to workaround this Max Sessions limitation for the Wireless endpoints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that a fair statement, or can you think of anything else we can use as a persistence ID on the F5 to accomplish this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2018 21:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505556#M517355</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-17T21:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505557#M517358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming same device used, then same user should be persisted to same PSN via Calling Station ID. As noted, there is a roadmap item.&amp;nbsp; Plan is to extend feature to node group/PSN cluster but details and timing need to be communicated privately by ISE PM team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 11:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505557#M517358</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-04-18T11:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 Max Sessions with distributed PSNs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505558#M517361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig. We're trying to ensure that sessions using different endpoints with the same username are stuck to the same PSN to be limited by the Max Sessions settings (particularly on Wireless), so it sounds like we'll have to use the NAS-IP for persistence ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll contact the ISE PMs for info on roadmap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 21:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-max-sessions-with-distributed-psns/m-p/3505558#M517361</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2018-04-18T21:11:37Z</dc:date>
    </item>
  </channel>
</rss>

