<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OCSP request to a specific TCP port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ocsp-request-to-a-specific-tcp-port/m-p/4430476#M568387</link>
    <description>&lt;P&gt;I have not tested this, but I dont see why it would not work.&amp;nbsp; As long as the responder is listening on that port I dont see this being an issue.&amp;nbsp; In the OCSP profile you are configuring the url to use.&amp;nbsp; I would recommend testing it by disabling this under the trusted cert/s for which you assign the OCSP profile to:&amp;nbsp;&lt;SPAN&gt;Reject the request if OCSP Responder is unreachable.&amp;nbsp; This way clients will remain unaffected.&amp;nbsp; Then once you confirm it works or does not work you can re-enable.&amp;nbsp; HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 12:17:38 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2021-07-09T12:17:38Z</dc:date>
    <item>
      <title>OCSP request to a specific TCP port</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-request-to-a-specific-tcp-port/m-p/4430455#M568385</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;We plan to place OCSP responder behind HA Proxy.&lt;/P&gt;&lt;P&gt;Is it possible to configure ISE to send ocsp requests to a specific TCP port for example 888?&lt;/P&gt;&lt;P&gt;In&amp;nbsp;&amp;nbsp;OCSP Profile&lt;/P&gt;&lt;P&gt;URL&amp;nbsp; &lt;A href="http://test.domai.com:888/ocsp" target="_blank" rel="noopener"&gt;http://test.domai.com:888/ocsp&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone tested it this way?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 11:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-request-to-a-specific-tcp-port/m-p/4430455#M568385</guid>
      <dc:creator>SemenErmachenko36396</dc:creator>
      <dc:date>2021-07-09T11:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP request to a specific TCP port</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-request-to-a-specific-tcp-port/m-p/4430476#M568387</link>
      <description>&lt;P&gt;I have not tested this, but I dont see why it would not work.&amp;nbsp; As long as the responder is listening on that port I dont see this being an issue.&amp;nbsp; In the OCSP profile you are configuring the url to use.&amp;nbsp; I would recommend testing it by disabling this under the trusted cert/s for which you assign the OCSP profile to:&amp;nbsp;&lt;SPAN&gt;Reject the request if OCSP Responder is unreachable.&amp;nbsp; This way clients will remain unaffected.&amp;nbsp; Then once you confirm it works or does not work you can re-enable.&amp;nbsp; HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 12:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-request-to-a-specific-tcp-port/m-p/4430476#M568387</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-07-09T12:17:38Z</dc:date>
    </item>
  </channel>
</rss>

