<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Ports Between Supplicant and ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887237#M582907</link>
    <description>&lt;P&gt;Do we need to allow any direct communication between ISE and the supplicant? On what port number?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know its radius between the authenticator and ISE ports 1812 and 1813&amp;nbsp;&lt;/P&gt;&lt;P&gt;but from the drawing below, there looks like traffic between the clients and ISE? what port number please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AhmedALJAWAD44875_0-1689708882994.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191708iEC305EB79DD93E87/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AhmedALJAWAD44875_0-1689708882994.png" alt="AhmedALJAWAD44875_0-1689708882994.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jul 2023 19:36:04 GMT</pubDate>
    <dc:creator>AhmedALJAWAD44875</dc:creator>
    <dc:date>2023-07-18T19:36:04Z</dc:date>
    <item>
      <title>Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887237#M582907</link>
      <description>&lt;P&gt;Do we need to allow any direct communication between ISE and the supplicant? On what port number?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know its radius between the authenticator and ISE ports 1812 and 1813&amp;nbsp;&lt;/P&gt;&lt;P&gt;but from the drawing below, there looks like traffic between the clients and ISE? what port number please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AhmedALJAWAD44875_0-1689708882994.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191708iEC305EB79DD93E87/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AhmedALJAWAD44875_0-1689708882994.png" alt="AhmedALJAWAD44875_0-1689708882994.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 19:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887237#M582907</guid>
      <dc:creator>AhmedALJAWAD44875</dc:creator>
      <dc:date>2023-07-18T19:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887256#M582908</link>
      <description>&lt;P&gt;There is no any kind of connection between client and ISE'&lt;/P&gt;
&lt;P&gt;The client send to SW or WLC EAPoL&lt;/P&gt;
&lt;P&gt;The SW/WLC will encapsulate it with radius message and send to ISE.&lt;/P&gt;
&lt;P&gt;So only 1813/1812 (use SE/wlc ip as source ) what you need.&lt;/P&gt;
&lt;P&gt;Only case that client connect to ISE is CWA ISE portal.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 22:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887256#M582908</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T22:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887261#M582909</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1129318"&gt;@AhmedALJAWAD44875&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You can check this guide for reference. There a few ports you may need to allow depending on the services you provide with ISE.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Cisco_SNS_3400_Series_Appliance_Ports_Reference.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/Cisco_SNS_3400_Series_Appliance_Ports_Reference.html&lt;/A&gt;&lt;/P&gt;
&lt;TABLE id="ID-1420-000000ee__table_EA24D484473D4A88B50A684662DA53FA" class="table" border="1" width="100%"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD class="entry align-left"&gt;
&lt;P class="p"&gt;Web Portal Services:&lt;/P&gt;
&lt;P class="p"&gt;- Guest/Web Authentication&lt;/P&gt;
&lt;P class="p"&gt;- Guest Sponsor Portal&lt;/P&gt;
&lt;P class="p"&gt;- My Devices Portal&lt;/P&gt;
&lt;P class="p"&gt;- Client Provisioning&lt;/P&gt;
&lt;P class="p"&gt;- Certificate Provisioning&lt;/P&gt;
&lt;P class="p"&gt;- BlackListing Portal&lt;/P&gt;
&lt;/TD&gt;
&lt;TD colspan="2" class="entry align-left"&gt;
&lt;P class="p"&gt;HTTPS (Interface must be enabled for service in Cisco ISE):&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID-1420-000000ee__li_480C2193E4C84C93805E6E6B9203982C" class="li"&gt;
&lt;P class="p"&gt;Blacklist Portal: TCP/8000-8999 (Default port is TCP/8444.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_82D31D9A82AE48E998ECF32213FCBA76" class="li"&gt;
&lt;P class="p"&gt;Guest Portal and Client Provisioning: TCP/8000-8999 (Default port is TCP/8443.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_32C12EC61BC747DFAB56D9C1D3FE0E32" class="li"&gt;
&lt;P class="p"&gt;Certificate Provisioning Portal: TCP/8000-8999 (Default port is TCP/8443.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_529F73D9B7BA4802A760AE112B06036A" class="li"&gt;
&lt;P class="p"&gt;My Devices Portal: TCP/8000-8999 (Default port is TCP/8443.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_3E0DAB8B65B44790BC1A56DE06C4A665" class="li"&gt;
&lt;P class="p"&gt;Sponsor Portal: TCP/8000-8999 (Default port is TCP/8443.)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_B0B7BDF195684948B0A43DFE184C00FA" class="li"&gt;
&lt;P class="p"&gt;SMTP guest notifications from guest and sponsor portals: TCP/25&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry align-left"&gt;
&lt;P class="p"&gt;Posture&lt;/P&gt;
&lt;P class="p"&gt;- Discovery&lt;/P&gt;
&lt;P class="p"&gt;- Provisioning&lt;/P&gt;
&lt;P class="p"&gt;- Assessment/ Heartbeat&lt;/P&gt;
&lt;/TD&gt;
&lt;TD colspan="2" class="entry align-left"&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID-1420-000000ee__li_35942055544A42008AB15C340740C0AF" class="li"&gt;
&lt;P class="p"&gt;Discovery (Client side): TCP/80 (HTTP), TCP/8905 (HTTPS)&lt;/P&gt;
&lt;TABLE class="olh_note" role="note" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="1%" class="olh_note"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD class="olh_note"&gt;
&lt;SECTION class="note__content"&gt;
&lt;P class="p"&gt;By default, TCP/80 is redirected to TCP/8443. See Web Portal Services: Guest Portal and Client Provisioning.&lt;/P&gt;
&lt;P class="p"&gt;Cisco ISE presents the Admin certificate for Posture and Client Provisioning on TCP port 8905.&lt;/P&gt;
&lt;P class="p"&gt;Cisco ISE presents the Portal certificate on TCP port 8443 (or the port that you have configured for portal use).&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_8415353BD49D43A499E5AF559D0575FC" class="li"&gt;
&lt;P class="p"&gt;Discovery (Policy Service Node side): TCP/8443, 8905 (HTTPS)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID-1420-000000ee__li_BE942B4996344391B0C5FD499E042EA5" class="li"&gt;
&lt;P class="p"&gt;Provisioning - URL Redirection: See Web Portal Services: Guest Portal and Client Provisioning&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_B34CCBE0B68843D8A517A86D5A28DC78" class="li"&gt;
&lt;P class="p"&gt;Provisioning - Active-X and Java Applet Install including IP refresh, Web Agent Install, and launch NAC Agent Install: See Web Portal Services: Guest Portal and Client Provisioning.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_623F67D42B4B4B1AB704742BDC0A01A4" class="li"&gt;
&lt;P class="p"&gt;Provisioning - NAC Agent Install: TCP/8443&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_CDF4E61CD7BB47C38588AA4F873B2CDC" class="li"&gt;
&lt;P class="p"&gt;Provisioning - NAC Agent Update Notification: UDP/8905&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_25E91D6075ED4FA183E07D748D9A7E43" class="li"&gt;
&lt;P class="p"&gt;Provisioning - NAC Agent and Other Package/Module Updates: TCP/8905 (HTTPS)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID-1420-000000ee__li_385F901D860E44F384E302A2D6925339" class="li"&gt;
&lt;P class="p"&gt;Assessment - Posture Negotiation and Agent Reports: TCP/8905 (HTTPS)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID-1420-000000ee__li_8A1F67C5B0214BF0956353836F898A77" class="li"&gt;
&lt;P class="p"&gt;Assessment - PRA/Keep-alive: UDP/8905&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 18 Jul 2023 19:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887261#M582909</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-18T19:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887267#M582910</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp; I need only client authentication using either EAP-TLS or MSCHAPv2.&lt;/P&gt;&lt;P&gt;Is there any ports required from the client to ISE for that? I don't see that in the design so I'm assuming no. please confirm.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887267#M582910</guid>
      <dc:creator>AhmedALJAWAD44875</dc:creator>
      <dc:date>2023-07-18T20:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887283#M582911</link>
      <description>&lt;P&gt;No direct communication to ISE, supplicant talks to authentication over EAP and authenticate talks to authentication server (ISE) using radius.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887283#M582911</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-07-18T20:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Ports Between Supplicant and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887322#M582915</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1129318"&gt;@AhmedALJAWAD44875&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For radius only, no need to open port between ISE and client&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 21:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/m-p/4887322#M582915</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-18T21:59:43Z</dc:date>
    </item>
  </channel>
</rss>

