<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSNs Not registering in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/4012763#M521445</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have exactly this problem and have followed the guide &amp;gt;&amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever fix the problem and how?&lt;/P&gt;&lt;P&gt;I am not 100% on what I am missing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jan 2020 15:30:49 GMT</pubDate>
    <dc:creator>Cobhamuser1</dc:creator>
    <dc:date>2020-01-16T15:30:49Z</dc:date>
    <item>
      <title>PSNs Not registering</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/3497512#M521443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In a distributed deployment, my PSNs are behind a pair of F5 LTMs configured in active/passive mode. The PSNs can &lt;/P&gt;&lt;P&gt;ping their gateway, the F5LTM VIP ip address and they can ping the DNS servers. However, they are not able to execute a successful nslookup either of the PAN or any other device in DNS and because of this registration to the PAN fails. The non-loadbalacing virtual servers on the F5 LTM show it passing traffic inbound and outbound without drops. Tcpdumps on the internal and external interfaces of the F5 LTM shows traffic indeed passes through. The DNS server is properly configured for forward and rever e lookups, We are running ISE 2.3 and v13.0 on the F5 LTM. What is preventing the PSNs from presenting a dns query to a dns server to which they have IP connectivity?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 00:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/3497512#M521443</guid>
      <dc:creator>david.e.jarvis</dc:creator>
      <dc:date>2017-09-20T00:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs Not registering</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/3497513#M521444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For starters, be sure to review the guides posted here on how to config F5 LTMs with ISE:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64434"&gt;ISE Load Balancing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The likely scenario is that you have not created an IP forwarding rule to allow the bidirectional DNS traffic, or tried to allow access via a virtual server connection.&amp;nbsp; If try to config as a virtual server, then even for UDP the LTM will treat the outbound request as a session and only allow reply from original target on same port/interface.&amp;nbsp;&amp;nbsp; Often drops are related to asymmetric flows (not taking exact path outbound and inbound through LTM), or more simply did not create a forwarding rule to allow the traffic to pass without inspections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that more specific rules will take precedence.&amp;nbsp; As you will see in guides, I am very prescriptive in the ports used, VLANs used, and IP addresses used.&amp;nbsp;&amp;nbsp; Also, if configure an IP forwarding rule &lt;EM&gt;after&lt;/EM&gt; other rules, it is possible that the traffic is being persisted by another policy and will not take the desired path/connection until you clear persistence cache or restart LB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 12:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/3497513#M521444</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-20T12:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: PSNs Not registering</title>
      <link>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/4012763#M521445</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have exactly this problem and have followed the guide &amp;gt;&amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever fix the problem and how?&lt;/P&gt;&lt;P&gt;I am not 100% on what I am missing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 15:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psns-not-registering/m-p/4012763#M521445</guid>
      <dc:creator>Cobhamuser1</dc:creator>
      <dc:date>2020-01-16T15:30:49Z</dc:date>
    </item>
  </channel>
</rss>

