<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not in a Link Aggregation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836079#M56384</link>
    <description>&lt;P&gt;Not in a Link Aggregation Group (LAG) or multichassis etherchannel such as your question implies.&lt;/P&gt;
&lt;P&gt;You can use the other Gigabit Ethernet ports beyond Gi0 but they each have to have a distinct IP address. There are various ways you can use these and some restrictions as well (i.e. Admin access to the PAN is restricted to Gi0).&lt;/P&gt;
&lt;P&gt;The details are laid out in a table here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Cisco_SNS_3400_Series_Appliance_Ports_Reference.html&lt;/P&gt;
&lt;P&gt;There are some Cisco Live presentations you can refer to for some design scenarios. I highly recommend Craig Hyps' &lt;A href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=83705&amp;amp;backBtn=true"&gt;BRKSEC-3699 Designing ISE for Scale and High Availability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=83705&amp;amp;backBtn=true&lt;/P&gt;</description>
    <pubDate>Tue, 29 Dec 2015 12:17:54 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-12-29T12:17:54Z</dc:date>
    <item>
      <title>ISE (SNS-3415-K9)  redundant NIC's</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836078#M56383</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; can we connect one SNS-3415-K9 (ISE) to &amp;nbsp;VSS switches . we have one ise (SNS-3415-K9) &amp;nbsp;server can we connect one interface(g1) to switch1 and another interface(g2) to switch2 for Redundant and load balancing ..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836078#M56383</guid>
      <dc:creator>sifathmirza</dc:creator>
      <dc:date>2019-03-11T06:21:35Z</dc:date>
    </item>
    <item>
      <title>Not in a Link Aggregation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836079#M56384</link>
      <description>&lt;P&gt;Not in a Link Aggregation Group (LAG) or multichassis etherchannel such as your question implies.&lt;/P&gt;
&lt;P&gt;You can use the other Gigabit Ethernet ports beyond Gi0 but they each have to have a distinct IP address. There are various ways you can use these and some restrictions as well (i.e. Admin access to the PAN is restricted to Gi0).&lt;/P&gt;
&lt;P&gt;The details are laid out in a table here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Cisco_SNS_3400_Series_Appliance_Ports_Reference.html&lt;/P&gt;
&lt;P&gt;There are some Cisco Live presentations you can refer to for some design scenarios. I highly recommend Craig Hyps' &lt;A href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=83705&amp;amp;backBtn=true"&gt;BRKSEC-3699 Designing ISE for Scale and High Availability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=83705&amp;amp;backBtn=true&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2015 12:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836079#M56384</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-29T12:17:54Z</dc:date>
    </item>
    <item>
      <title>Hi .</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836080#M56385</link>
      <description>&lt;P&gt;Hi .&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Cisco ISE management is restricted to Gigabit Ethernet 0.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;RADIUS listens on all network interface cards (NICs).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;All NICs can be configured with IP addresses.&lt;/P&gt;
&lt;SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="fignone"&gt;That means &amp;nbsp;can we connect Gi0 ,Gi1 to VSS switch1 and Gi2 to VSS switch2 . if switch1 goes down we can't access ISE &amp;nbsp;but &amp;nbsp;still ISE listens RADIUS from Gi2(switch2). Please suggest me&amp;nbsp;the connectivity of standalone ISE in VSS environment ..&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 04 Jan 2016 04:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836080#M56385</guid>
      <dc:creator>sifathmirza</dc:creator>
      <dc:date>2016-01-04T04:46:42Z</dc:date>
    </item>
    <item>
      <title>If you have a single node</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836081#M56386</link>
      <description>&lt;P&gt;If you have a single node currently and want ISE high availability the recommended solution is a two node deployment. &amp;nbsp;You need only deploy a second VM and join it to the deployment. Then node one connects to switch 1 and likewise node two connects to switch 2.&lt;/P&gt;
&lt;P&gt;The use of the various NICs is not part of ISE's high availability scheme. Most single node deployments simply use only the Gi0 NIC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 12:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836081#M56386</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-01-04T12:56:25Z</dc:date>
    </item>
    <item>
      <title>Thank You Marvin Rhoads .</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836082#M56387</link>
      <description>&lt;P&gt;Thank You Marvin Rhoads .&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if i have a single node (SNS-3415-K9 ISE Appliance) &amp;nbsp;i use Gi0 NIC , &amp;nbsp;can you please tell me the use of the remaining three NIC's . if &amp;nbsp;i want to use that NIC's &amp;nbsp;for assigning particular services, can i assign ? &amp;nbsp;if we can assign , HOW .&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Thank you ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 11:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836082#M56387</guid>
      <dc:creator>sifathmirza</dc:creator>
      <dc:date>2016-01-13T11:55:07Z</dc:date>
    </item>
    <item>
      <title>For basic RADIUS connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836083#M56388</link>
      <description>&lt;P&gt;For basic RADIUS connectivity, you can just assign an IP address to the interface from the cli. If you need to reach remote subnets via that interface, you also need to add static route(s). The syntax for both is defined in the ISE Command Line Interface Reference guide:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp3087188604&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can also assign your portals to use the various NICs via the portal configuration page (assuming you've already setup IP addresses and/or routes as noted above). See screenshot below (from an ISE 2.0 standalone deployment on a VM).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_portal_nic_assignment.png" class="migrated-markup-image" /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 13:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sns-3415-k9-redundant-nic-s/m-p/2836083#M56388</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-01-13T13:48:43Z</dc:date>
    </item>
  </channel>
</rss>

