<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE setup using a Load balancer in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-setup-using-a-load-balancer/m-p/3441919#M521357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We want to setup ISE PSNs behind a loadbalancer( Netscaler or F5). For COA, do we need to add default route on PSNs towards loadbalancer IP? How should we route traffic from PSNs if we are using SNAT, i.e. default route should be towards ? If we are using SNAT, how will PSN determine the IP of NAD device? I am not sure of ISE 2.3, but till ISE 2.2, ISE doesn't have the capability to get the real NAD IP from Radius header. It uses the IP header info to determine the NAD IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see some documents mentioning SNAT is possible for COA? But I don't see how it works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions/links will be really appreciable...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Sep 2017 13:29:38 GMT</pubDate>
    <dc:creator>manoj.k@pwc.com</dc:creator>
    <dc:date>2017-09-22T13:29:38Z</dc:date>
    <item>
      <title>ISE setup using a Load balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-setup-using-a-load-balancer/m-p/3441919#M521357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We want to setup ISE PSNs behind a loadbalancer( Netscaler or F5). For COA, do we need to add default route on PSNs towards loadbalancer IP? How should we route traffic from PSNs if we are using SNAT, i.e. default route should be towards ? If we are using SNAT, how will PSN determine the IP of NAD device? I am not sure of ISE 2.3, but till ISE 2.2, ISE doesn't have the capability to get the real NAD IP from Radius header. It uses the IP header info to determine the NAD IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see some documents mentioning SNAT is possible for COA? But I don't see how it works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions/links will be really appreciable...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 13:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-setup-using-a-load-balancer/m-p/3441919#M521357</guid>
      <dc:creator>manoj.k@pwc.com</dc:creator>
      <dc:date>2017-09-22T13:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE setup using a Load balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-setup-using-a-load-balancer/m-p/3441920#M521361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you look at our F5 doc in the community?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=1&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0ahUKEwiI84nd9LjWAhXB54MKHaDTB7QQFgg0MAA&amp;amp;url=https%3A%2F%2Fcommunities.cisco.com%2Fdocs%2FDOC-68198&amp;amp;usg=AFQjCNGkPpG_T9t2A8hsHRgz73zTxMFqig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 13:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-setup-using-a-load-balancer/m-p/3441920#M521361</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-22T13:37:10Z</dc:date>
    </item>
  </channel>
</rss>

