cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
617
Views
0
Helpful
1
Replies

Cisco ISE - F5 LTM - Supported Topologies

mkim1
Level 1
Level 1

We are exploring using our F5s to load balance authentication requests to our ISE nodes.

Looking at this How To (https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159), it looks like only physical or logically inline topologies are supported.

Is this possible without an inline topology? Has anyone added F5 load balancing to an existing ISE deployment in production?

Thank you.

1 Reply 1

davidgfriedman
Level 1
Level 1

I have an old legacy ISE deployment which does this using policy based routing.  Of course the ISE VLAN SVI is on the same layer 3 switches as the F5 SVI, making this possible. We route udp/1812, udp/1813, and in reverse the CoA ports through the F5.  No issues here with that configuration.