cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1801
Views
0
Helpful
8
Replies

Connecting a pxGrid client to natted pxGrid node IP

victguti
Level 1
Level 1

Hello,

My customer cannot connect FMC 5.4.1.5 (pxGrid client) and ISE (1.3) pxGrid node directly and needs to use NAT for this. Therefore, the pxGrid client  will point to the natted IP of pxGrid node. There will be any problem for pxGrid client registration?

Thanks,

Víctor.

1 Accepted Solution

Accepted Solutions

Hey Viktor,

You can try, i don't think will work, verifying with development.

Thanks,

John

jeppich@cisco.com

View solution in original post

8 Replies 8

kthiruve
Cisco Employee
Cisco Employee

Both PxGrid client and server require certificates. I have reached out the SME on this. You will see a response soon.

-Krishnan

Hey Krishnan, Victor.

The FMC client requires connection to port TCP/5222 of the ISE pxGrid node.

Thanks,
John

jeppich@cisco.com

Hi John,

Many thanks. Certificates are configured in pxGrid node and pxGrid client and yes, we opened the TCP/5222 port in the firewall but performing network address translation to ISE node. It means, pxGrid client doesn't point to the real pxGrid node IP address but to the natted IP. Do you think it will cause an issue on pxGrid node registration?

Thanks,

Víctor.

Sent from my Samsung Galaxy smartphone.

Hey Viktor,

You can try, i don't think will work, verifying with development.

Thanks,

John

jeppich@cisco.com

Hey Viktor,

I stand corrected, development says you should be good.

Thanks,

John

jeppich@cisco.com

You would need to make sure DNS resolves to the ip address of the address that the PXgrid client is trying to communicate with. This DNS name is what is present in the certificate. Otherwise there will be a mismatch and it will fail.

Any systems in the non natted environment (same internal network as ISE) would need to resolve to the internal IP

Hi Jason,

They use the same DNS servers for FMC and ISE nodes and they resolve to the internal pxGrid node IP address...

Adding the natted IP to the A DNS record already existent would be ok?

Thanks,

Víctor.

Hey John,

Great, many thanks. I will try and let you know in any case.

Best regards,

Víctor.

Sent from my Samsung Galaxy smartphone.