<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic trace route to ISE interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765478#M579492</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I am attempting to do a trace route from a switch to an interface I have on a my ISE server however it is getting blocked. Does ISE (v2.6.0.156) have some sort of firewall that could be blocking the trace attempt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jan 2023 22:37:23 GMT</pubDate>
    <dc:creator>benbroadfoot</dc:creator>
    <dc:date>2023-01-30T22:37:23Z</dc:date>
    <item>
      <title>trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765478#M579492</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I am attempting to do a trace route from a switch to an interface I have on a my ISE server however it is getting blocked. Does ISE (v2.6.0.156) have some sort of firewall that could be blocking the trace attempt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 22:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765478#M579492</guid>
      <dc:creator>benbroadfoot</dc:creator>
      <dc:date>2023-01-30T22:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765504#M579493</link>
      <description>&lt;P&gt;first try ping,&lt;BR /&gt;are ping success ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 23:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765504#M579493</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-30T23:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765508#M579494</link>
      <description>&lt;P&gt;yes it pings fine, just stops on tracert - see png&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 00:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765508#M579494</guid>
      <dc:creator>benbroadfoot</dc:creator>
      <dc:date>2023-01-31T00:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765592#M579495</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1406092"&gt;@benbroadfoot&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;about "&lt;EM&gt; ... &lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;have some sort of firewall that could be blocking the trace attempt...&lt;/EM&gt; " ...&amp;nbsp;&lt;/SPAN&gt;at &lt;STRONG&gt;CLI&lt;/STRONG&gt;, use the following command and search for &lt;STRONG&gt;iptables&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;ise/admin# show tech-support&lt;BR /&gt;...&lt;BR /&gt;*****************************************&lt;BR /&gt;Running &lt;STRONG&gt;iptables&lt;/STRONG&gt; -nvL...&lt;BR /&gt;*****************************************&lt;BR /&gt;...&lt;/PRE&gt;
&lt;P&gt;Note: I'm able to &lt;EM&gt;traceroute&lt;/EM&gt; an &lt;STRONG&gt;ISE&lt;/STRONG&gt; on version &lt;STRONG&gt;2.7&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Hope this helps !!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 01:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765592#M579495</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-01-31T01:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765626#M579497</link>
      <description>&lt;P&gt;Thanks for the info&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;I have attached a screen shot of the start of the iptables section of the tech-support - what am I looking for exactly?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 04:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765626#M579497</guid>
      <dc:creator>benbroadfoot</dc:creator>
      <dc:date>2023-01-31T04:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765924#M579508</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1406092"&gt;@benbroadfoot&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;the &lt;STRONG&gt;iptables&lt;/STRONG&gt; looks fine !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Please try the following two options:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. If you have another &lt;STRONG&gt;ISE Node&lt;/STRONG&gt;, try to &lt;EM&gt;traceroute&lt;/EM&gt; from &lt;STRONG&gt;Node 2&lt;/STRONG&gt; to &lt;STRONG&gt;Node 1&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;&lt;STRONG&gt;iseNode2&lt;/STRONG&gt;/admin# traceroute &lt;U&gt;&lt;EM&gt;&amp;lt;IP Addr of iseNode1&amp;gt;&lt;/EM&gt;&lt;/U&gt;&lt;BR /&gt;traceroute to &lt;U&gt;&lt;EM&gt;&amp;lt;IP Addr of iseNode1&amp;gt;&lt;/EM&gt;&lt;/U&gt; (&lt;U&gt;&lt;EM&gt;&amp;lt;IP Addr of iseNode1&amp;gt;&lt;/EM&gt;&lt;/U&gt;), 30 hops max, 60 byte packets&lt;BR /&gt;1 &lt;U&gt;&lt;EM&gt;&amp;lt;IP Addr of iseNode1&amp;gt;&lt;/EM&gt;&lt;/U&gt; 0.469 ms 0.450 ms 0.449 ms&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. try to &lt;EM&gt;traceroute&lt;/EM&gt; from your &lt;STRONG&gt;PC&lt;/STRONG&gt; to &lt;STRONG&gt;Node 1&lt;/STRONG&gt;&amp;nbsp;(using the following command) to check if the packet arrives at&amp;nbsp;&lt;STRONG&gt;Node 1&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;&lt;STRONG&gt;iseNode1&lt;/STRONG&gt;/admin# tech dumptcp 0 | inc ICMP&lt;BR /&gt;&lt;BR /&gt;10:35:05.130657 IP (tos 0x48, ttl 1, id 61535, offset 0, flags [none], proto ICMP (1), length 92)&lt;BR /&gt;&lt;EM&gt;&lt;U&gt;&amp;lt;your PC IP Addr&amp;gt;&lt;/U&gt;&lt;/EM&gt; &amp;gt; &lt;EM&gt;&lt;U&gt;&amp;lt;IP Addr oof iseNode1&amp;gt;&lt;/U&gt;&lt;/EM&gt;: ICMP echo request, id 1, seq 255, length 72&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 13:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765924#M579508</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-01-31T13:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765976#M579510</link>
      <description>&lt;P&gt;friend use traceroute with source IP&lt;BR /&gt;source IP is the IP you add to ISE for router/SW&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 15:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4765976#M579510</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-31T15:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4766246#M579515</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;not sure why I didn't try this initially! I AM able to tracert to the ISE interface from a PC so I'm guessing the issue isn't with ISE at all. Strange it will not allow me from a switch but will allow me from a PC?&lt;/P&gt;&lt;P&gt;Thanks again for your tips!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 21:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4766246#M579515</guid>
      <dc:creator>benbroadfoot</dc:creator>
      <dc:date>2023-01-31T21:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: trace route to ISE interface</title>
      <link>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4766321#M579519</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1406092"&gt;@benbroadfoot&lt;/a&gt;&amp;nbsp;, glad to be of help !!!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 02:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trace-route-to-ise-interface/m-p/4766321#M579519</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-02-01T02:27:17Z</dc:date>
    </item>
  </channel>
</rss>

