01-31-2017 02:41 AM
Hello,
My customer cannot connect FMC 5.4.1.5 (pxGrid client) and ISE (1.3) pxGrid node directly and needs to use NAT for this. Therefore, the pxGrid client will point to the natted IP of pxGrid node. There will be any problem for pxGrid client registration?
Thanks,
Víctor.
Solved! Go to Solution.
01-31-2017 01:56 PM
Hey Viktor,
You can try, i don't think will work, verifying with development.
Thanks,
John
01-31-2017 12:51 PM
Both PxGrid client and server require certificates. I have reached out the SME on this. You will see a response soon.
-Krishnan
01-31-2017 01:39 PM
Hey Krishnan, Victor.
The FMC client requires connection to port TCP/5222 of the ISE pxGrid node.
Thanks,
John
01-31-2017 01:46 PM
Hi John,
Many thanks. Certificates are configured in pxGrid node and pxGrid client and yes, we opened the TCP/5222 port in the firewall but performing network address translation to ISE node. It means, pxGrid client doesn't point to the real pxGrid node IP address but to the natted IP. Do you think it will cause an issue on pxGrid node registration?
Thanks,
Víctor.
Sent from my Samsung Galaxy smartphone.
01-31-2017 01:56 PM
Hey Viktor,
You can try, i don't think will work, verifying with development.
Thanks,
John
01-31-2017 03:02 PM
01-31-2017 03:06 PM
You would need to make sure DNS resolves to the ip address of the address that the PXgrid client is trying to communicate with. This DNS name is what is present in the certificate. Otherwise there will be a mismatch and it will fail.
Any systems in the non natted environment (same internal network as ISE) would need to resolve to the internal IP
02-02-2017 07:26 AM
Hi Jason,
They use the same DNS servers for FMC and ISE nodes and they resolve to the internal pxGrid node IP address...
Adding the natted IP to the A DNS record already existent would be ok?
Thanks,
Víctor.
01-31-2017 03:12 PM
Hey John,
Great, many thanks. I will try and let you know in any case.
Best regards,
Víctor.
Sent from my Samsung Galaxy smartphone.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide