<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Encryption Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3738494#M536728</link>
    <description>&lt;P&gt;The certificates designated with the usage "Admin".&lt;/P&gt;</description>
    <pubDate>Sat, 03 Nov 2018 17:16:56 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-11-03T17:16:56Z</dc:date>
    <item>
      <title>ISE Encryption Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3419460#M536725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have some questions about the traffic flows for ISE and encryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source : All ISE Nodes&lt;/P&gt;&lt;P&gt;Destination : All ISE Nodes&lt;/P&gt;&lt;P&gt;Port : TCP 12001&lt;/P&gt;&lt;P&gt;Purpose : ISE Configuration replication&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question : Is this over TLS?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source : All ISE Nodes&lt;/P&gt;&lt;P&gt;Destination : All ISE Nodes&lt;/P&gt;&lt;P&gt;Port : TCP 7802&lt;/P&gt;&lt;P&gt;Purpose : ISE Configuration replication&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question : Is this over TLS?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source : Admin&amp;amp;Mon&lt;/P&gt;&lt;P&gt;Destination : Admin&amp;amp;Mon&lt;/P&gt;&lt;P&gt;Port : TCP 1528&lt;/P&gt;&lt;P&gt;Purpose :&amp;nbsp; Oracle DB (Secure JDBC)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Questions : Is this over TLS? Need to understand what "secure" means.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Dec 2016 19:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3419460#M536725</guid>
      <dc:creator>Wade Vick</dc:creator>
      <dc:date>2016-12-12T19:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Encryption Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3419461#M536726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JGroups communications over TCP/12001 (global JGroup channel) and TCP/7800 and 7802 (Local JGroup Cluster) all occur over TLS 1.2.&amp;nbsp; Oracle communications over JDBC are also secured via TLS.&amp;nbsp; All current (patched) versions of ISE should address current SSL vulnerabilities including the use of TLS to secure internode communications.&amp;nbsp; Depending on the service, there are some options to deliberately allow weaker protocols and ciphers for backwards compatibility, for example TLS 1.0 or SHA-1 user, but default should be secure (disallow SSL).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2016 00:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3419461#M536726</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-12-13T00:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Encryption Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3738043#M536727</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry to wake up an old thread, but which certs are used for the encryption? The certs imported as part of adding the nodes to the primary PAN?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I wanted to use my own certs from a private CA, is there a guide for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 15:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3738043#M536727</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-11-02T15:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Encryption Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3738494#M536728</link>
      <description>&lt;P&gt;The certificates designated with the usage "Admin".&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 17:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-encryption-questions/m-p/3738494#M536728</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-03T17:16:56Z</dc:date>
    </item>
  </channel>
</rss>

