01-11-2021 10:23 PM
Guys, looking for DC-DR static IP solution for Anyconnect VPN clients.
Current architecture is
Anyconnect <> DC ASA <> DC ISE <> Corp AD
Anyconnect user gets a static IP. IP is binded to static IP properties of AD user in Dial-in Tab.
DC ISE fetches this IP (192.168.31.x range) and passes on to the user. Till now it's working perfectly.
Now, we are setting up another ASA in DR, now the architecture becomes;
Anyconnect <> DR ASA <> DR ISE <> Corp AD
this time the anyconnect user should get IP in the range 172.16.x.x range.
Anyone any idea how this can be worked out. AD user properties lets store only one IP address.
Solved! Go to Solution.
01-13-2021 05:34 AM - edited 01-13-2021 05:44 AM
@manvik Out of curiousity and to confirm my thoughts, I've tested it and it works as expected.
msRADIUSFramedIPAddress just relates to the attribute under the Dial-in tab in AD, it seems you can use any attribute under the users account in AD, as long as you import them into ISE. I imagine you could use custom schema attributes also.
HTH
01-11-2021 11:12 PM
01-12-2021 09:03 PM
Thank you @Mohammed al Baqari
I think the feasible option is " assign the static IPs using ISE (Frame-IP) on a per user basis". Question is how do we assign static IP in ISE for an AD user.
01-12-2021 09:47 PM
01-12-2021 12:07 AM - edited 01-12-2021 12:07 AM
01-12-2021 09:04 PM
Thank you @Rob Ingram let me test this.
01-13-2021 05:34 AM - edited 01-13-2021 05:44 AM
@manvik Out of curiousity and to confirm my thoughts, I've tested it and it works as expected.
msRADIUSFramedIPAddress just relates to the attribute under the Dial-in tab in AD, it seems you can use any attribute under the users account in AD, as long as you import them into ISE. I imagine you could use custom schema attributes also.
HTH
01-14-2021 05:58 AM
Thank you @Rob Ingram It worked like a charm.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide