<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: My Devices Portal with Multiple PSNs F5 Load Balanced in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864817#M582630</link>
    <description>&lt;P&gt;You can have portal hosted on gig1.&lt;/P&gt;
&lt;P&gt;Are you load balancing only RADIUS traffic? The initial authentication request and the web redirection should happen on the same PSN. Check if the RADIUS request and the web redirection is happening on the same PSN.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2023 18:01:42 GMT</pubDate>
    <dc:creator>Nancy Saini</dc:creator>
    <dc:date>2023-06-29T18:01:42Z</dc:date>
    <item>
      <title>My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864108#M582595</link>
      <description>&lt;P&gt;We have a 6 node ISE deployment, which includes 4 PSNs. They are load balanced via an F5 load balancer&lt;BR /&gt;&lt;BR /&gt;For the My Devices Portal setup would I need to create a new F5 VIP and load balance it between the PSNs I choose?&lt;/P&gt;&lt;P&gt;Is there an option besides creating a new F5 VIP? I ask because with the PSNs being load balanced their default route is pointing back towards the F5 gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 16:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864108#M582595</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2023-06-28T16:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864119#M582596</link>
      <description>&lt;P&gt;You would need virtual IP on LB as it will serve as a catch all for these traffic flows and perform IP forwarding.&lt;/P&gt;
&lt;P&gt;MDM being a URL-redirected web services uses ISE sessionization. It uses an Audit Session ID to track the lifecycle of an endpoint’s connection between a network access device and a specific PSN. URL Redirection with sessionization requires that endpoints are redirected to a specific PSN that “owns” the session. During RADIUS authorization, the PSN processing the connection may return a URL Redirect that includes its own FQDN and unique Audit Session ID. This tells the client exactly which PSN to attempt direct HTTPS access and informs the receiving PSN which specific RADIUS session the request pertains.&lt;/P&gt;
&lt;P&gt;Reference : &lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 17:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864119#M582596</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-06-28T17:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864255#M582603</link>
      <description>&lt;P&gt;You don't need a new VIP for portals, they can use the same VIP as RADIUS, but you would want to define a virtual server for port 8443. Source IP persistence takes care of this use case. Your my devices portal fqdn should resolve the F5 VIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 21:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864255#M582603</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2023-06-28T21:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864260#M582604</link>
      <description>&lt;P&gt;So that would be using the same VIP, but configure the virtual for 8443? Would the pool members also be configured for 8443?&lt;BR /&gt;&lt;BR /&gt;For the Source IP Persistence are you referring to SNAT being turned off or setting the persistence profile to use source address?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 21:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864260#M582604</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2023-06-28T21:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864285#M582605</link>
      <description>&lt;P&gt;I got a VIP set up. The URL/FQDN for the portal is reachable, but I keep getting an error: "[ 404 ] Resource Not Found. The resource requested cannot be found."&lt;BR /&gt;&lt;BR /&gt;I have two interfaces on my ISE VMs. One being GigabitEthernet 0 for the management interface and the other being GigabitEthernet 1 facing the F5 load balancer. Does the portal need to be using the Gig 1 interface?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 23:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864285#M582605</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2023-06-28T23:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864817#M582630</link>
      <description>&lt;P&gt;You can have portal hosted on gig1.&lt;/P&gt;
&lt;P&gt;Are you load balancing only RADIUS traffic? The initial authentication request and the web redirection should happen on the same PSN. Check if the RADIUS request and the web redirection is happening on the same PSN.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 18:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864817#M582630</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-06-29T18:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864838#M582633</link>
      <description>&lt;P&gt;I'm testing it out on the test deployment we have which is two nodes. We do have VIPs for RADIUS. The issue I can see is that it's just going to &lt;A href="https://community.cisco.com/" target="_blank"&gt;https://&amp;lt;URL&amp;gt;:8443/portal/&lt;/A&gt;&amp;nbsp;instead of https://&amp;lt;URL&amp;gt;:8443/mydevices/PortalSetup.action?portal=..........&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 18:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4864838#M582633</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2023-06-29T18:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: My Devices Portal with Multiple PSNs F5 Load Balanced</title>
      <link>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4868119#M582687</link>
      <description>&lt;P&gt;It only worked after I had a VIP created for port 443 as well.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 15:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/my-devices-portal-with-multiple-psns-f5-load-balanced/m-p/4868119#M582687</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2023-07-05T15:03:22Z</dc:date>
    </item>
  </channel>
</rss>

