cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3150
Views
0
Helpful
5
Replies

Can I use ISE IPN without posture for VPN with Base license only?

valrerod
Level 1
Level 1

I'm looking at ISE licensing, and both Base and Advanced licenses have VPN listed. I could not find any document that provides guideline for VPN implementation using ISE Base license only.

1. Can I use ISE IPN (Inline Posture Node) functionality without posture assessment with ISE Base license only? (I know it has to be ISE hardware appliance, and I know that Posture assessment requires ISE Advanced license.)

2. Do I have to use IPN for VPN deployment using ISE as the Radius server?

3. If I do not have to use IPN for VPN, can I use ISE for Authentication and Authorization in the same way as I use ACS?

Thanks,

Val Rodionov

5 Replies 5

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

When using vpn without posturing you do not need the IPN since you will authenticate users only. IPN is only for posturing vpn clients.

This will only require a base license since this is a feature on requires basic radius authentication.

Tarik Admani
*Please rate helpful posts*

Hi Tarik,

Thank you for answering my questions.

Now I understand that with ISE Base license VPN user authentication.

Can you clarify:

-Can IPN be used without posturing and apply "inline" policies based on user group?

-Does IPN installation require Advanced license?

Thanks,

Val

Val,

There is no need to consider IPN if you are not using posturing. You can use ISE much like ACS for radius authentication for vpn users.

If posturing is down the road and your hope is to have an architecture in place and license later, then I am sure that you can use the ipn with base licensing, however I would strongle recommend working with the PDI (for partners) for help and confirmation.

Thanks,

Tarik Admani
*Please rate helpful posts*

Hi Tarik,

I was contemplating installing IPN with ISE Base license. I had configured several IPNs in the past, but I did not know if the IPN could be used with base license. I'll veriy that with PDI or TAC.

Thank you for answering my questions!

Thanks,

Val

Venkatesh Attuluri
Cisco Employee
Cisco Employee

An Inline Posture node is a gatekeeper that enforces access policies and handles  change of authorization (CoA) requests

The Base license is intended for organizations that want to authenticate and  authorize users and devices on their network (wired, wireless, and VPN)