<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE appliance connected to Nexus switches in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/4067197#M559679</link>
    <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if this query belongs in the ISE discussion or the Switching area....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to connect my ISE appliance with a Bond to two Nexus N9K switches for resilience.&amp;nbsp; The N9K switches are configured as a VPC pair.&amp;nbsp; I read from other discussions that 'vpc orphan-port suspend' should be configured on the switches to deal correctly with certain failure scenarios, but I can't find any more information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do the two N9K switchports get configured as stand-alone orphan ports, or do I configure them as a proper vPC (switchports added to a static Port-channel on each switch, then linked together with the 'vpc x' command), and add the 'suspend' command to the port-channels on each switch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What should I expect to see when connected up - the N9K switchport connected to the active ISE port will be 'Up' and passing traffic, but will the switchport connected to the passive ISE port show in an 'up' or 'down' state?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use the Bond interface for both Mangement and Runtime traffic, I understand that each function needs to have a different IP address.&amp;nbsp; Should they be on the same vlan / subnet in this scenario?&amp;nbsp; If different vlans, the switchport will need to be a trunk, so which vlan should be the Native vlan?&amp;nbsp; Will the ISE appliance tag both vlans appropriately?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 13:30:04 GMT</pubDate>
    <dc:creator>ianjgrant</dc:creator>
    <dc:date>2020-04-16T13:30:04Z</dc:date>
    <item>
      <title>ISE appliance connected to Nexus switches</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/4067197#M559679</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if this query belongs in the ISE discussion or the Switching area....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to connect my ISE appliance with a Bond to two Nexus N9K switches for resilience.&amp;nbsp; The N9K switches are configured as a VPC pair.&amp;nbsp; I read from other discussions that 'vpc orphan-port suspend' should be configured on the switches to deal correctly with certain failure scenarios, but I can't find any more information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do the two N9K switchports get configured as stand-alone orphan ports, or do I configure them as a proper vPC (switchports added to a static Port-channel on each switch, then linked together with the 'vpc x' command), and add the 'suspend' command to the port-channels on each switch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What should I expect to see when connected up - the N9K switchport connected to the active ISE port will be 'Up' and passing traffic, but will the switchport connected to the passive ISE port show in an 'up' or 'down' state?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use the Bond interface for both Mangement and Runtime traffic, I understand that each function needs to have a different IP address.&amp;nbsp; Should they be on the same vlan / subnet in this scenario?&amp;nbsp; If different vlans, the switchport will need to be a trunk, so which vlan should be the Native vlan?&amp;nbsp; Will the ISE appliance tag both vlans appropriately?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 13:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/4067197#M559679</guid>
      <dc:creator>ianjgrant</dc:creator>
      <dc:date>2020-04-16T13:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE appliance connected to Nexus switches</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/4081133#M560193</link>
      <description>Through much trial and error, I have established the following:&lt;BR /&gt;&lt;BR /&gt;Although the interfaces are bound together at the appliance end, the switch end should not be configured as a bond - just treat them as two independent interfaces. For a N9K VPC pair, this means no VPC commands, and the 'vpc orphan-port suspend' command should be configured on both switches. Both switchports will show as UP, and Connected, but the MAC address will only be seen on the switchport attached to the Active ISE interface.&lt;BR /&gt;&lt;BR /&gt;I have decided to keep the CIMC traffic on the dedicated interface, so will not have to deal with vlans on the Bonded interfaces.&lt;BR /&gt;&lt;BR /&gt;Hopefully this may aid someone else in future.</description>
      <pubDate>Thu, 07 May 2020 09:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/4081133#M560193</guid>
      <dc:creator>ianjgrant</dc:creator>
      <dc:date>2020-05-07T09:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE appliance connected to Nexus switches</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/5128328#M589965</link>
      <description>&lt;P&gt;Is it not so easy to get the information that you should have plain "switchport access" configuration on the connecting switchports to the ISE appliance. I started with portchannel configuration on the switchports and get severe connection problems.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 06:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-appliance-connected-to-nexus-switches/m-p/5128328#M589965</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2024-06-11T06:00:22Z</dc:date>
    </item>
  </channel>
</rss>

