<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Design that utilizes a dedicated interface per persona. Is it vali in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665731#M576597</link>
    <description>&lt;P&gt;I agree that would make the most sense in a normal situation, but in this case we are mimicking a separate network that would use all the exact same IPs (these networks do not touch the internet). The network we are mimicking is larger and has 10 dedicated nodes, whereas as this one will be condensed to 5 nodes. This is why we had to assign 2 nodes with multiple personas. The idea is to make both cubes look almost identical. I wanted to experiment, but if it does not work I will most likely bundle the interfaces.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 13:28:23 GMT</pubDate>
    <dc:creator>Walker</dc:creator>
    <dc:date>2022-08-08T13:28:23Z</dc:date>
    <item>
      <title>Design that utilizes a dedicated interface per persona. Is it valid?</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665707#M576591</link>
      <description>&lt;P&gt;The design of our new ISE cube has two SNS-3655 nodes that will act as the Admin/MnT/PSN on each. I am wondering if it is possible to run 3 dedicated connections to the appliance to separate the traffic based on the persona. When I look in the deployment settings, it doesn't seem you can set which interface you would like for that service, but my thinking is that you can set it up in the configuration to accomplish this. For example, for Admin nothing will change, MnT change the logging/remote logging settings to the second interface, and for the PSN we can just configure the switches to point to the third interface. Has anyone configured something similar to this, and if so, does it pose any problems? Unfortunately I do not have a lab to test this on, so your input is greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 12:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665707#M576591</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2022-08-08T12:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Design that utilizes a dedicated interface per persona. Is it vali</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665721#M576595</link>
      <description>&lt;LI-CODE lang="markup"&gt; I am wondering if it is possible to run 3 dedicated connections to the appliance to separate the traffic based on the persona.&lt;/LI-CODE&gt;
&lt;P&gt;what is the use case here, instead why not make a Bundle interfaces to get high availability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 13:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665721#M576595</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-08T13:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Design that utilizes a dedicated interface per persona. Is it vali</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665731#M576597</link>
      <description>&lt;P&gt;I agree that would make the most sense in a normal situation, but in this case we are mimicking a separate network that would use all the exact same IPs (these networks do not touch the internet). The network we are mimicking is larger and has 10 dedicated nodes, whereas as this one will be condensed to 5 nodes. This is why we had to assign 2 nodes with multiple personas. The idea is to make both cubes look almost identical. I wanted to experiment, but if it does not work I will most likely bundle the interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 13:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665731#M576597</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2022-08-08T13:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Design that utilizes a dedicated interface per persona. Is it vali</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665736#M576598</link>
      <description>&lt;P&gt;Do you high level diagram what you trying to achieve ? (may be as per the information, that is not possible i know...but wait for other mates comments and any one tried this ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 13:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665736#M576598</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-08T13:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Design that utilizes a dedicated interface per persona. Is it vali</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665993#M576601</link>
      <description>&lt;P&gt;I &lt;EM&gt;&lt;STRONG&gt;think&lt;/STRONG&gt;&lt;/EM&gt; I know what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/485442"&gt;@Walker&lt;/a&gt;&amp;nbsp;is trying to do here ... but I am also wondering what the point is. It's highly unlikely that a single 1GE or even 10GE interface on this UCS appliance will get a lot of traffic to warrant separating the interfaces. Bonding is the only thing I would consider to provide some resilience in the case where separate uplinks can be connected to two independent switches on the same VLAN.&lt;/P&gt;
&lt;P&gt;ISE make use of iptables under the hood to protect/firewall the traffic that comes in on interfaces. Gig0/Bond0 is always used for management - and the other interfaces are typically used for guest portals.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"All roads lead to Rome" - as the saying goes - what are we trying to achieve by separating the traffic out on individual interfaces? Avoiding the use of a router perhaps?&amp;nbsp; I think you're going to make life very tricky for yourself - I did that once and ended up with static routes on ISE nodes - it was unpleasant and you quickly and painfully learn how the product works when you deviate from the norm.&amp;nbsp; I don't understand why OVAs ship with 6 virtual NICs - I always delete all of them and add a single VMXNET3 - in 99.9% of the cases that works great.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 20:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4665993#M576601</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-08-08T20:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Design that utilizes a dedicated interface per persona. Is it vali</title>
      <link>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4666686#M576615</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/485442"&gt;@Walker&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"for academic purposes only",&amp;nbsp; : )&amp;nbsp; ... let's put &lt;STRONG&gt;Multiple Interfaces&lt;/STRONG&gt; and &lt;STRONG&gt;Bond&lt;/STRONG&gt; all together to try to answer your question:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;.&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;ISE Management&lt;/STRONG&gt;&amp;nbsp;is restricted to&amp;nbsp;&lt;STRONG&gt;Gigabit Ethernet 0 (Eth0)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;All NICs&lt;/STRONG&gt; can be configured with &lt;STRONG&gt;IP Addr&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;Bond&lt;/STRONG&gt; configuration:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth0&lt;/STRONG&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth2&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;must be assigned an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IPv4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IPv6&lt;/STRONG&gt;) address (&lt;STRONG&gt;Primary Interface&lt;/STRONG&gt;) and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth1&lt;/STRONG&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth3&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Eth5&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;must not be assigned an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IP&amp;nbsp;Addr&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;Backup Interface&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;.&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;RADIUS&lt;/STRONG&gt;&amp;nbsp;listens on all&amp;nbsp;&lt;STRONG&gt;NICs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. configure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Bond0&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;Eth0+Eth1&lt;/STRONG&gt;) for&amp;nbsp;&lt;STRONG&gt;ISE Management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;PRE&gt;ise/admin(config)# interface GigabitEthernet 0 &lt;BR /&gt;ise/admin(config-GigabitEthernet)# backup interface GigabitEthernet 1 &lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Guest Portals&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to point to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Bond1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;Eth2+Eth3&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Work Centers&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Guest Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Portal &amp;amp; Components&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Guest Portal&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;... select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Portal Settings&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Bond1&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NADs&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to send the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;RADIUS&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;packets to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Bond2&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;Eth4+Eth5&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 01:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/design-that-utilizes-a-dedicated-interface-per-persona-is-it/m-p/4666686#M576615</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-08-10T01:10:02Z</dc:date>
    </item>
  </channel>
</rss>

