<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Smart Licensing via http proxy - deeper dive in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578643#M519430</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what version of ISE is this. Couple of things, I think the URL is hardcorded and since it is https, you cannot see via Wireshark captures. I have reached out to Engineering on the defect. Will update you more once I find.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Dec 2017 03:36:40 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2017-12-01T03:36:40Z</dc:date>
    <item>
      <title>ISE Smart Licensing via http proxy - deeper dive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578642#M519429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Smart Licensing is cool and we're busy converting all of our traditional licenses to Smart.&amp;nbsp; We're also using Smart on Cisco Prime. &lt;/P&gt;&lt;P&gt;The challenge I am having is that in my environment, all internet traffic needs to go via an internal Proxy.&amp;nbsp; The preferred scenario is that the proxy is authenticated (username/password). ISE supports this because I can configure a proxy with user credentials. I have tested this and I was able to use it for my SMS gateway feature which lives on the internet.&lt;/P&gt;&lt;P&gt;But the proxy doesn't work with Smart Licensing.&amp;nbsp; I have taken countless tcpdumps and eventually logged a TAC case.&amp;nbsp; There is a bug CSCvd93008 related to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround my customer said that they would whitelist the ISE PAN(s) to allow unauthenticated access through the proxy.&amp;nbsp; But when we tried to allow tools.cisco.com the Smart Licensing didn't work. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question:&amp;nbsp; What is the FULL URL that ISE tries to access when talking to Cisco for Smart Licensing?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know http and https that well, but I think a client will build a TLS connection to tools.cisco.com first, and only once the TLS tunnel is established it will try to POST/GET/whatever to the final URL. And if that's the case, we cannot see that in a tcpdump because the session is encrypted.&amp;nbsp; Maybe that's why the URL filter won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what then should the proxy whitelisting URL contain?&amp;nbsp; Is it even possible, or can one only whitelist the FQDN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#life_is_easy_without_proxies_getting_in_the_way&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 01:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578642#M519429</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-30T01:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Smart Licensing via http proxy - deeper dive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578643#M519430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what version of ISE is this. Couple of things, I think the URL is hardcorded and since it is https, you cannot see via Wireshark captures. I have reached out to Engineering on the defect. Will update you more once I find.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 03:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578643#M519430</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-12-01T03:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Smart Licensing via http proxy - deeper dive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578644#M519431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi this is ISE 2.3 patch 1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2017 22:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578644#M519431</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-12-03T22:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Smart Licensing via http proxy - deeper dive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578645#M519432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see your TAC case is making progress and you already have the correct URL for the Smart Licensing site. Please continue working with TAC. I will write to TAC with my comments.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Dec 2017 03:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-smart-licensing-via-http-proxy-deeper-dive/m-p/3578645#M519432</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-05T03:04:24Z</dc:date>
    </item>
  </channel>
</rss>

