08-17-2017 03:17 AM - edited 03-11-2019 12:57 AM
Hi,
I'm trying to design a DMZ and security architecture that will incorporate a distributed deployment of ISE.
Assuming that each network segment will have a PSN deployed locally within it, is there any way to configure an individual PSN to consult the local network segment domain controller and name resolution service rather than having to open the firewalls to let every deployed PSN look "up" to a DC elsewhere on the network?
I've attached a concept sketch of what I want to achieve.
Thanks,
Solved! Go to Solution.
08-22-2017 11:20 AM
Hi,
ISE is Active Directory Sites and Services aware, so if you configure the ISE subnet in the same site as the local DC it should query this local DC. Whether at somepoint the ISE would need to query another DC is a good question and may need further investigation.
HTH
Rob
08-22-2017 11:20 AM
Hi,
ISE is Active Directory Sites and Services aware, so if you configure the ISE subnet in the same site as the local DC it should query this local DC. Whether at somepoint the ISE would need to query another DC is a good question and may need further investigation.
HTH
Rob
08-23-2017 01:19 PM
I would say the answer is yes but still you need to open firewall for traffic between PSN's and Admin Nodes regarding for instance, authentication logs. In addition to that, NTP running for example on windows DC does not work well with ISE devices. Take this into consideration.
08-25-2017 01:40 AM
Thanks - As per the correct answer, location awareness via AD should give a predictable pattern to build an ACL on. For info's sake - the Microsoft registry hacks to turn a Windows server into an NTP server have worked pretty well for me.
08-25-2017 02:49 AM
Just to add to the discussion - you can also specify preferred DCs for each PSN using the AD connector Advanced Tuning tool. It is usually recommended to rely on AD sites though.
08-25-2017 04:08 AM
That's good to know - thanks
08-25-2017 09:41 AM
We have had issues with the ISE synchronizing NTP with the Win Domain Controller. Do you have any link so I can check the tweak you mentioned?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: