
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-21-2019 06:02 AM
We have a customer who has F5 and PSNs in LTM mode but are doing an SNAT for incoming radius traffic hence all radius requests appear to come from the F5. This is because F5 and PSNs are separated by L3 and are not physically inline.
However it is always recommended to not have SNAT for incoming radius traffic.
Is it possible to have F5 not be physically inline to the PSNs (F5 is not the default gateway of the PSNs) and still avoid SNAT for radius ?
F5 being physically inline to the PSNs as shown in the below guide has always worked for me.
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2019 06:38 PM
Yes, it is possible although does have some additional traffic engineering challenges. More info in the F5-Cisco ISE Load Balancing Guide and in BRKSEC-3699 (Reference presentation) posted to CiscoLive.com.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-03-2019 06:38 PM
Yes, it is possible although does have some additional traffic engineering challenges. More info in the F5-Cisco ISE Load Balancing Guide and in BRKSEC-3699 (Reference presentation) posted to CiscoLive.com.
