<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Load Balancing Radius traffic to ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490945#M535759</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not supported today IF you need functions like CoA to work.&amp;nbsp; The reasons are discussed in the guide as well as reference version of BRKSEC-3699 posted to CiscoLive.com.&amp;nbsp; The short reason is that CoA is returned to the NAD IP which ISE believes to be LB in the SNAT case.&amp;nbsp; LB drops it as there is no other destination in packet header.&amp;nbsp; Please reach out to your Cisco sales team and ask them to add your company's name to the following enhancement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;User Story 8601 &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;: CoA support for &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;NAT'ed&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt; load balanced environments&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 May 2017 19:22:09 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-05-26T19:22:09Z</dc:date>
    <item>
      <title>Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490942#M535756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; As far as I understand to use multiple PSNs I need to place a load balancer in front&amp;nbsp; of the PSNs. I'd like to use a "central" load balancer with source NAT by adding&amp;nbsp; a new Radius AV pair with&amp;nbsp; the source IP ( or tell ISE to use an already existing attribute for the source IP).&amp;nbsp; Is that possible i.e. Can I tell ISE to uas a Radius attribute as source IP of the connection instead of the UDP packet IP ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2017 10:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490942#M535756</guid>
      <dc:creator>MAMO</dc:creator>
      <dc:date>2017-05-26T10:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490943#M535757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Markus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the below document for additional information on load balancing with ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64434"&gt;ISE Load Balancing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2017 17:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490943#M535757</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-05-26T17:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490944#M535758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I looked at the documents already and did not find it ( or did I overlooked it ) . i.e.&amp;nbsp; I saw the F5 SNAT option for communication from the PSNs back to the switch. But I am interested in the other way round from the switch to the PSN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2017 17:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490944#M535758</guid>
      <dc:creator>MAMO</dc:creator>
      <dc:date>2017-05-26T17:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490945#M535759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not supported today IF you need functions like CoA to work.&amp;nbsp; The reasons are discussed in the guide as well as reference version of BRKSEC-3699 posted to CiscoLive.com.&amp;nbsp; The short reason is that CoA is returned to the NAD IP which ISE believes to be LB in the SNAT case.&amp;nbsp; LB drops it as there is no other destination in packet header.&amp;nbsp; Please reach out to your Cisco sales team and ask them to add your company's name to the following enhancement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;User Story 8601 &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;: CoA support for &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;NAT'ed&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt; load balanced environments&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2017 19:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490945#M535759</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-26T19:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490946#M535760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thank&amp;nbsp; you for the information.&amp;nbsp; I'll check the COA case which I am also&amp;nbsp; interested in .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; But COA is from the PSN to the switch.&amp;nbsp; I am looking for the other direction i.e. when the switch send the Radius request to the LB and the LB to a PSN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2017 19:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490946#M535760</guid>
      <dc:creator>MAMO</dc:creator>
      <dc:date>2017-05-26T19:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490947#M535761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. I am referring to same use case.&amp;nbsp; Forget about the SNAT for CoA for the moment.&amp;nbsp; The issue is SNAT for NAD will cause all CoA to fail--regardless of whether you choose to SNAT CoA or not.&amp;nbsp; Be sure to review BRKSEC-3699 (reference version).&amp;nbsp; My summation statement is...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SNAT for NAD is BAD&lt;/P&gt;&lt;P&gt;SNAT for CoA is OK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 May 2017 00:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490947#M535761</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-27T00:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490948#M535762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chyps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Apologies I looked at the wrong pages,&amp;nbsp;&amp;nbsp; I see now on page 279 the comment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt; &lt;EM&gt;NAS IP Address is correct, but not currently used for CoA &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; So what do I have to do to support an enhancement request to use the NAS-IP. Where do I find details about&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;User Story 8601 : CoA support for NAT'edload balanced environments&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 May 2017 10:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490948#M535762</guid>
      <dc:creator>MAMO</dc:creator>
      <dc:date>2017-05-27T10:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490949#M535763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please reach out to your Cisco sales team and ask them to add your company's name to the following enhancement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;User Story 8601 &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;: CoA support for &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt;NAT'ed&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.0pt; font-family: Arial; color: #0070c0;"&gt; load balanced environments&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 May 2017 15:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490949#M535763</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-27T15:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balancing Radius traffic to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490950#M535764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 May 2017 15:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/load-balancing-radius-traffic-to-ise/m-p/3490950#M535764</guid>
      <dc:creator>MAMO</dc:creator>
      <dc:date>2017-05-27T15:50:59Z</dc:date>
    </item>
  </channel>
</rss>

