<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE PSN load balancing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103274#M561220</link>
    <description>Anurag,&lt;BR /&gt;&lt;BR /&gt;I used those guides to setup the F5 and that's when I ran into the problem. Right now the NAD keeps flapping between radius server dead and radius server alive</description>
    <pubDate>Mon, 15 Jun 2020 12:03:36 GMT</pubDate>
    <dc:creator>donald.heslop1</dc:creator>
    <dc:date>2020-06-15T12:03:36Z</dc:date>
    <item>
      <title>ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103053#M561203</link>
      <description>&lt;P&gt;Has anyone figured out a way to load balance PSNs behind a F5 load balancer? I looked at some configuration guides and they are all for F5 11.4. I'm using version 13.0 so the direction a not valid from my situation. The main issue I am having is posturing and COA from the PSNs behind the F5. My switch is not getting the COA request from the PSNs even though I have the "correct" SNAT on the F5 so my NADs should be getting COA from the VIP on the F5. Unfortunately that is not happening so after my posture scan completes and the supplicant is compliant the NAD doesn't receive the COA so no re-authentication happens on the port and the device is stuck in my remediation vlan until I force a new scan via anyconnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luckily this is a POC so it not effecting live production. Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 02:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103053#M561203</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-06-15T02:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103076#M561205</link>
      <description>I've had customers run ISE behind a range of F5's versions, up to 14.1, with no issues.  &lt;BR /&gt;&lt;BR /&gt;Are you not seeing the COA at the NAD at all, or just coming direct from the node and not masked from the VIP IP? Need to determine if it's a F5 issue or if ISE is not sending the COA in the first place.</description>
      <pubDate>Mon, 15 Jun 2020 04:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103076#M561205</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-15T04:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103258#M561217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/422222"&gt;@donald.heslop1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I would urge you to take a look at the following posts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/configuring-f5-ltm-for-cisco-ise-load-balancing/ta-p/3642134" target="_blank"&gt;https://community.cisco.com/t5/security-documents/configuring-f5-ltm-for-cisco-ise-load-balancing/ta-p/3642134&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200317-F5-LTM-loadbalancing-Radius-and-HTTP-tra.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200317-F5-LTM-loadbalancing-Radius-and-HTTP-tra.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Furthermore, for your problem, try to take capture at every point (ISE, F5, switch) to determine what's happening with the CoA.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 11:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103258#M561217</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-15T11:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103274#M561220</link>
      <description>Anurag,&lt;BR /&gt;&lt;BR /&gt;I used those guides to setup the F5 and that's when I ran into the problem. Right now the NAD keeps flapping between radius server dead and radius server alive</description>
      <pubDate>Mon, 15 Jun 2020 12:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103274#M561220</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-06-15T12:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103275#M561221</link>
      <description>&lt;P&gt;Damien,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I create a SNAT rule on the F5 (per documentation) so that the PSNs will be translated to the VIP. Are you doing posturing as well at your customers or just authentication?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 14:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103275#M561221</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-06-15T14:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103280#M561222</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/422222"&gt;@donald.heslop1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;For the "flapping" issue, please enable the following debug and check the logs where it complains about the 'Timed-Out':&lt;/P&gt;
&lt;P&gt;debug radius&lt;/P&gt;
&lt;P&gt;term mon&lt;/P&gt;
&lt;P&gt;Ideally, you should take packet captures too to identify who's not responding (or responding incorrectly).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 12:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103280#M561222</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-15T12:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103310#M561224</link>
      <description>&lt;P&gt;Anurag,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a packtet capture from my POC from the PSN to the NAD. I see the source port (coming from the PSN behind the F5) is 30026. Shouldn't that be udp 1700?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 13:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103310#M561224</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-06-15T13:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103465#M561233</link>
      <description>Source port will be randomly selected, only the destination port will be 1700, so that is correct minus no SNAT.</description>
      <pubDate>Mon, 15 Jun 2020 15:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103465#M561233</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-15T15:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PSN load balancing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103469#M561234</link>
      <description>Yes, I've seen all services be used with F5's including posture.  &lt;BR /&gt;&lt;BR /&gt;What has worked well for me is creating a snat pool list with the F5 VIP as the only IP. Then a separate forwarding ip virtual server for each psn referencing the source address of the PSN, and server port 1700. In this you also reference the snat pool list.  It correctly masks coa's from the VIP.  &lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2020 15:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-psn-load-balancing/m-p/4103469#M561234</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-15T15:19:53Z</dc:date>
    </item>
  </channel>
</rss>

