<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multi LNS server IP balanced by ISE response in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543888#M527719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you are right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with David Li, who is the local Security Expert in China Team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is the LAC that decide how to load-balancing between the LNS addresses returned from the attribute 67.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="4" cellspacing="0" frame="border" rules="all" style="margin-top: 8pt; margin-bottom: 10pt; color: #000000; font-family: 'PingFang SC'; font-size: 16px;" summary=""&gt;&lt;TBODY style="font-size: 11pt;"&gt;&lt;TR&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.1 " valign="top" width="15%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;67&lt;/P&gt;&lt;/TD&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.2 " valign="top" width="31.666666666666664%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;Tunnel-Server-Endpoint&lt;/P&gt;&lt;/TD&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.3 " valign="top" width="53.333333333333336%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;IP address of the LNS that establishes a tunnel. The IP address is in dotted decimal notation. A tag can deliver a maximum of eight IP addresses, with each IP address separated by a space. Multiple IP addresses work in primary/secondary mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Aug 2017 16:29:05 GMT</pubDate>
    <dc:creator>Weiborao</dc:creator>
    <dc:date>2017-08-10T16:29:05Z</dc:date>
    <item>
      <title>multi LNS server IP balanced by ISE response</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543887#M527718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Hi, Dear ISE Experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; font-family: Helvetica, Arial, sans-serif; font-size: 14px;"&gt;My customer have L2TP authentication requirement, need ISE to return LNS server IP to LAC. Customer have multiple LNS servers, hope ISE can return LNS server IP with round robin. Does ISE support it?&lt;/P&gt;&lt;P style="color: #666666; font-family: Helvetica, Arial, sans-serif; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #666666; font-family: Helvetica, Arial, sans-serif; font-size: 14px;"&gt;If not support round robin, does ISE support returning multiple LNS IP addresses to the LAC ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; font-family: Helvetica, Arial, sans-serif; font-size: 14px;"&gt;BTW, all LAC authentication will use same user name with no password.(or we can say no authentication required)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; font-family: Helvetica, Arial, sans-serif; font-size: 14px;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 15:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543887#M527718</guid>
      <dc:creator>Weiborao</dc:creator>
      <dc:date>2017-08-10T15:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: multi LNS server IP balanced by ISE response</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543888#M527719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you are right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with David Li, who is the local Security Expert in China Team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is the LAC that decide how to load-balancing between the LNS addresses returned from the attribute 67.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="4" cellspacing="0" frame="border" rules="all" style="margin-top: 8pt; margin-bottom: 10pt; color: #000000; font-family: 'PingFang SC'; font-size: 16px;" summary=""&gt;&lt;TBODY style="font-size: 11pt;"&gt;&lt;TR&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.1 " valign="top" width="15%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;67&lt;/P&gt;&lt;/TD&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.2 " valign="top" width="31.666666666666664%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;Tunnel-Server-Endpoint&lt;/P&gt;&lt;/TD&gt;&lt;TD class="cellrowborder" headers="mcps1.6.2.2.2.4.1.3 " valign="top" width="53.333333333333336%"&gt;&lt;P style="margin-top: 0.2em; margin-bottom: 0.2em;"&gt;IP address of the LNS that establishes a tunnel. The IP address is in dotted decimal notation. A tag can deliver a maximum of eight IP addresses, with each IP address separated by a space. Multiple IP addresses work in primary/secondary mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543888#M527719</guid>
      <dc:creator>Weiborao</dc:creator>
      <dc:date>2017-08-10T16:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: multi LNS server IP balanced by ISE response</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543889#M527720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please consult with the support teams for the network device platform as to the specifics to return from a RADIUS server.&lt;/P&gt;&lt;P&gt;For instance, &lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/vpdn/configuration/12-4/vpd-12-4-book/Configuring_AAA_for_VPDNs.html#GUID-F4CD2EBC-3CE1-4FA4-B0B6-41380141AD51"&gt;VPDN Configuration Guide, Cisco IOS Release 12.4 - Configuring AAA for VPDNs [Cisco IOS Software Releases 12.4 Mainline] - Cisco&lt;/A&gt; mentions to use either Cisco VSA (cisco-av-pair) or RADIUS tunnel attributes. The examples I found are all using very old ACS releases, but I believe they would be similar to the following ISE authorization profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-08-12 at 8.16.01 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/110459_Screen Shot 2017-08-12 at 8.16.01 PM.png" style="height: 434px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-08-12 at 8.35.47 PM.png" class="jive-image image-2" src="/legacyfs/online/fusion/110460_Screen Shot 2017-08-12 at 8.35.47 PM.png" style="height: auto; width: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 03:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543889#M527720</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-13T03:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: multi LNS server IP balanced by ISE response</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543890#M527721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, hslai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for you reply and contribution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 09:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-lns-server-ip-balanced-by-ise-response/m-p/3543890#M527721</guid>
      <dc:creator>Weiborao</dc:creator>
      <dc:date>2017-08-13T09:56:59Z</dc:date>
    </item>
  </channel>
</rss>

