<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE dedicate Guest Interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158430#M591166</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt; the traffic to/from the Eth0 interface would be routed via the gateway defined with the default-gateway command. Whereas traffic to/from the dedicated interface for the guest portal would use the gateway as per ip route command.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 13:41:12 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-08-09T13:41:12Z</dc:date>
    <item>
      <title>Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158416#M591161</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our customer has two Cisco ISE deployeds like this:&lt;/P&gt;
&lt;P&gt;Gig0: Management Only (HTTPS/SSH), TACACS+/RADIUS to/from NADs and Guest&lt;/P&gt;
&lt;P&gt;We need to configure a separate interface for Guest Access in the DMZ, so the configuration will be like this:&lt;/P&gt;
&lt;P&gt;Gig0: Management Only (HTTPS/SSH), TACACS+/RADIUS&lt;/P&gt;
&lt;P&gt;Gig2: Guest Interface (Tied to WebAuth Portal)&lt;/P&gt;
&lt;P&gt;Its necessary to create static route for my guest interface?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158416#M591161</guid>
      <dc:creator>Leonardo Santana</dc:creator>
      <dc:date>2024-08-09T13:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158418#M591162</link>
      <description>&lt;P&gt;Check this&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/cisco-ise-ip-interfaces-configuration/td-p/4034493" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/cisco-ise-ip-interfaces-configuration/td-p/4034493&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158418#M591162</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-09T13:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158422#M591163</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt; yes, you need to configure a static route on each PSN hosting the Guest portal for traffic to/from dedicated the guest interface using the command&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;ip route 0.0.0.0 0.0.0.0 &amp;lt;next hop ip&amp;gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158422#M591163</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-09T13:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158425#M591164</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;
&lt;P&gt;Thanks for your answer. After configuring the ip route how ISE will select the correct interface at show ip route?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158425#M591164</guid>
      <dc:creator>Leonardo Santana</dc:creator>
      <dc:date>2024-08-09T13:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158426#M591165</link>
      <description>&lt;P&gt;Friend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check link you will get answer for your Q' there is also ciscolive check it&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158426#M591165</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-09T13:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158430#M591166</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt; the traffic to/from the Eth0 interface would be routed via the gateway defined with the default-gateway command. Whereas traffic to/from the dedicated interface for the guest portal would use the gateway as per ip route command.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158430#M591166</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-09T13:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158447#M591167</link>
      <description>&lt;P&gt;Rob,&lt;/P&gt;
&lt;P&gt;Like this, a ip route 0.0.0.0 0.0.0.0 pointing to he default gw of my guest network.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/cli_guide/b_ise_CLIReferenceGuide_27/b_ise_CLIReferenceGuide_27_chapter_011.html#wp3952387991" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/cli_guide/b_ise_CLIReferenceGuide_27/b_ise_CLIReferenceGuide_27_chapter_011.html#wp3952387991&lt;/A&gt;&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;ISE InterfaceIPNetworkGateway
192.168.114.10 192.168.114.0 192.168.114.1
192.168.115.10 192.168.115.0 192.168.115.1
192.168.116.10 192.168.116.0 192.168.116.1
192.168.117.10 192.168.117.0 192.168.117.1


&lt;/CODE&gt;&lt;/PRE&gt;
&lt;SECTION class="p"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="keyword kwd"&gt;ip route&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command is used here to define default routes for each interface.
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;
ise/admin(config)# ip route 0.0.0.0 0.0.0.0 192.168.114.1
ise/admin(config)# ip route 0.0.0.0 0.0.0.0 192.168.115.1
ise/admin(config)# ip route 0.0.0.0 0.0.0.0 192.168.116.1
ise/admin(config)# ip route 0.0.0.0 0.0.0.0 192.168.117.1
ise/admin(config)# ip default-gateway 192.168.118.1&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Fri, 09 Aug 2024 14:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158447#M591167</guid>
      <dc:creator>Leonardo Santana</dc:creator>
      <dc:date>2024-08-09T14:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158461#M591168</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt; example from an implementation I designed, where Gi1 interface was dedicated for Guest traffic.&lt;/P&gt;
&lt;P&gt;PSN-1/admin (config)# interface GigabitEthernet 1&lt;BR /&gt;PSN-1/admin (config-GigabitEthernet)# ip address 172.21.1.68 255.255.255.224&lt;/P&gt;
&lt;P&gt;% Changing the IP address might cause ise services to restart&lt;BR /&gt;Continue with IP address change? Y/N [N]: Y&lt;/P&gt;
&lt;P&gt;------SERVICES RESTART-------&lt;/P&gt;
&lt;P&gt;PSN-1/admin (config-GigabitEthernet)# exit&lt;BR /&gt;PSN-1/admin (config)# ip route 0.0.0.0 0.0.0.0 172.21.1.65&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 14:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158461#M591168</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-09T14:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE dedicate Guest Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158472#M591169</link>
      <description>&lt;P&gt;we always configure default route via G0 and 1 or more static routes for guest user subnets via G2 in your case and it works.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 14:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dedicate-guest-interface/m-p/5158472#M591169</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2024-08-09T14:42:04Z</dc:date>
    </item>
  </channel>
</rss>

