<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static FQDN for portal with F5 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452841#M569192</link>
    <description>&lt;P&gt;From my standpoint, this is a guest access, meaning that it will happen only for guest users. It also means that it will happen only upon initial connection, so it is not like users are connected all the time to this guest portal. If you want to achieve load-balancing, you could achieve it via WiFi setup, instructing WLC to use all configured AAA servers for this SSID, which should effectivelly achive te same - WLC would send requests to both PSNs. PSNs would then reply, each with their own FQDN.&lt;/P&gt;&lt;P&gt;You could also look into imeplementing 'sleeping clients' approach, so that you actually cache some users, for certain perion, and not to prompt them for authentication, each time they step away from WiFi.&lt;/P&gt;&lt;P&gt;Placing ISE behind LB is not same like placing standard Web server behind LB. Reason for that is that LB can't just overwrite IP header, but it needs to modify the RADIUS content as well. This is why that guide is relevant, if you still want to proceed with it. For me personally, it looks like too much effort, without actually gaining much.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Sat, 21 Aug 2021 10:44:10 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2021-08-21T10:44:10Z</dc:date>
    <item>
      <title>Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4451925#M569146</link>
      <description>&lt;P&gt;&amp;nbsp;Hi to everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my question is simple. Is it possible to do without problem assign to a guest-portal a static fqdn that point to the VIP F5 address? In order to balance the load trought F5? between two PSN.&lt;/P&gt;&lt;P&gt;(behind this F5 we have all PSN that provide the portal page)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 15:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4451925#M569146</guid>
      <dc:creator>Fabio885</dc:creator>
      <dc:date>2021-08-19T15:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452091#M569154</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1019118"&gt;@Fabio885&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, it is possible to assign static IP or FQDN as part of authorization profile on ISE.&lt;/P&gt;&lt;P&gt;However, placing ISE behind load-balancer is not that straight forward, and it must not be done as on standard Web servers. Please take a look at this &lt;A href="https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159" target="_self"&gt;design guide&lt;/A&gt;, in order to understand how ISE can be placed behind LB for RADIUS service.&lt;/P&gt;&lt;P&gt;If I may ask, what is your driver for doing this for Guest portal? What are you looking to achieve with this?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 20:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452091#M569154</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-08-19T20:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452418#M569177</link>
      <description>&lt;P&gt;Thank you for replying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, what do you mean with "driver"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btw i need to investigate on "400Bad request".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 12:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452418#M569177</guid>
      <dc:creator>Fabio885</dc:creator>
      <dc:date>2021-08-20T12:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452452#M569179</link>
      <description>&lt;P&gt;Why do you want to place Guest portal behind LB?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 13:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452452#M569179</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-08-20T13:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452465#M569180</link>
      <description>&lt;P&gt;We need a LB because we have 2 psn for site. Are sites many populated with multiple office and we want to balance the load.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 13:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452465#M569180</guid>
      <dc:creator>Fabio885</dc:creator>
      <dc:date>2021-08-20T13:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Static FQDN for portal with F5</title>
      <link>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452841#M569192</link>
      <description>&lt;P&gt;From my standpoint, this is a guest access, meaning that it will happen only for guest users. It also means that it will happen only upon initial connection, so it is not like users are connected all the time to this guest portal. If you want to achieve load-balancing, you could achieve it via WiFi setup, instructing WLC to use all configured AAA servers for this SSID, which should effectivelly achive te same - WLC would send requests to both PSNs. PSNs would then reply, each with their own FQDN.&lt;/P&gt;&lt;P&gt;You could also look into imeplementing 'sleeping clients' approach, so that you actually cache some users, for certain perion, and not to prompt them for authentication, each time they step away from WiFi.&lt;/P&gt;&lt;P&gt;Placing ISE behind LB is not same like placing standard Web server behind LB. Reason for that is that LB can't just overwrite IP header, but it needs to modify the RADIUS content as well. This is why that guide is relevant, if you still want to proceed with it. For me personally, it looks like too much effort, without actually gaining much.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 10:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/static-fqdn-for-portal-with-f5/m-p/4452841#M569192</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-08-21T10:44:10Z</dc:date>
    </item>
  </channel>
</rss>

