cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
899
Views
0
Helpful
2
Replies

Authenticate from NAT outside endpoint

azhakama
Cisco Employee
Cisco Employee

I want to confirm if it is possible to authenticate from NAT inside endpoints but also from outside endpoints(which have Global IP address).

It seems to work if ISE is Static NATed, but is it supported structure?

                                                                          Outside<- | ->Inside

Global IP address endpoints --- GW(Global IP)-----| NAT Router |---- ISE(Static NATed) |----- Private IP address endpoints(PATed)

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

NNot officially tested but has been working for years

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

NNot officially tested but has been working for years

azhakama
Cisco Employee
Cisco Employee

Thank you for the reply. Could you kindly tell me what type of authentication is used ?

My customer's environment is going to be MAB, Web Auth, dot1x mixed. These are on Wired and Wireless.

And in the future, they are planning to use Dynamic VLAN, Downloadable ACL or Trustsec.

It still seems working fine when ISE is Static NATed, however, please let me know if there is any known issue.