<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creation of secondary IP or IP loopback with /32 on ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523977#M519199</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE supports multiple interfaces which can be assigned unique IP in its own subnet but loopbacks and secondaries not supported.&amp;nbsp; You mention ACE, so potentially sounds like trying to replicate a DSR config which also is not supported by ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Dec 2017 20:35:01 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-12-12T20:35:01Z</dc:date>
    <item>
      <title>Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523973#M519195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is migrating from ACS to ISE. They need to create a secondary host IP address (/32) or loopback on ISE to provide an access to. Is it possible to do it? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alexey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 12:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523973#M519195</guid>
      <dc:creator>Alexey Babaytsev</dc:creator>
      <dc:date>2017-12-12T12:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523974#M519196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t think so, is there a reason they cannot create another interface and configure that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523974#M519196</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-12T14:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523975#M519197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer needs to assign a host address to ISE because this address was used by ACE before (from different network segment). But for LAN communication (VRRP and so on) usual address /27 should be used also. These addresses are totally different addresses.&lt;/P&gt;&lt;P&gt;Idea is to use /27 address for LAN communication and /32 address for using by network devices for TACACS service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alexey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523975#M519197</guid>
      <dc:creator>Alexey Babaytsev</dc:creator>
      <dc:date>2017-12-12T15:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523976#M519198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now I don’t see an option for secondary or loopback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Management must reside on gig0 but other traffic can take place on other interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a reason they can’t create another interface and use that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523976#M519198</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-12T15:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523977#M519199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE supports multiple interfaces which can be assigned unique IP in its own subnet but loopbacks and secondaries not supported.&amp;nbsp; You mention ACE, so potentially sounds like trying to replicate a DSR config which also is not supported by ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523977#M519199</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-12-12T20:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523978#M519200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig.&lt;/P&gt;&lt;P&gt;Does it mean that ISE doesn’t support /32 addresses at all?&lt;/P&gt;&lt;P&gt;Sorry for typo – I meant ACS, not ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alexey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523978#M519200</guid>
      <dc:creator>Alexey Babaytsev</dc:creator>
      <dc:date>2017-12-12T20:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523979#M519201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;/32 is not the same as a loopback or secondary.&amp;nbsp; You should be able to config /32, but not sure if it will achieve desired result.&amp;nbsp; ISE will not forward traffic between interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523979#M519201</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-12-12T20:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Creation of secondary IP or IP loopback with /32 on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523980#M519202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alexey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still confused on what the customer is trying to do. Is the customer trying to do a flash but by using the same address on ISE that was used&amp;nbsp; in ACS so they don't have to go and touch all their network equipment to change TACACS IPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 13:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/creation-of-secondary-ip-or-ip-loopback-with-32-on-ise/m-p/3523980#M519202</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-12-13T13:14:28Z</dc:date>
    </item>
  </channel>
</rss>

