12-19-2023 07:19 AM
Hi,
We are planning to integrate the Envoy tool to integrate with ISE to automate the guest authentication.
For this, in the Envoy guide it require a public IP for the ISE admin node.
Our setup is behind a firewall and we would need to allow the specific rule in the firewall for the Envoy to communicate.
Is there any risk associated with this setup and any impact to be expected if anyone is having experience with integrating the Envoy tool.
Thanks,
Prathap
Solved! Go to Solution.
12-19-2023 12:14 PM
I've integrated Envoy with other NAC providers but not with ISE specifically. There is always risk associated to opening anything up directly to the internet. That being said proper firewall policy, inspection, etc should mitigate that risk to some degree. Also be sure to keep your ISE deployment upgraded and patched.
12-19-2023 12:14 PM
I've integrated Envoy with other NAC providers but not with ISE specifically. There is always risk associated to opening anything up directly to the internet. That being said proper firewall policy, inspection, etc should mitigate that risk to some degree. Also be sure to keep your ISE deployment upgraded and patched.
02-02-2024 06:37 AM
You can limit the risk by only allowing the IPs provided in the Envoy documentation to access the ISE node externally.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide