cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

658
Views
0
Helpful
1
Replies
Highlighted
Cisco Employee

F5 ISE integration

We have a customer who has F5 and PSNs in LTM mode but are doing an SNAT for incoming radius traffic hence all radius requests appear to come from the F5. This is because F5 and PSNs are separated by L3 and are not physically inline. 

 

However it is always recommended to not have SNAT for incoming radius traffic.

Is it possible to have F5 not be physically inline to the PSNs (F5 is not the default gateway of the PSNs) and still avoid SNAT for radius ?

 

F5 being physically inline to the PSNs as shown in the below guide has always worked for me.

 

https://community.cisco.com/t5/security-documents/how-to-cisco-amp-f5-deployment-guide-ise-load-balancing-using/ta-p/3631159#toc-hId--500784889

 

 

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Beginner

Yes, it is possible although does have some additional traffic engineering challenges.  More info in the F5-Cisco ISE Load Balancing Guide and in BRKSEC-3699 (Reference presentation) posted to CiscoLive.com.

View solution in original post

1 REPLY 1
Highlighted
Beginner

Yes, it is possible although does have some additional traffic engineering challenges.  More info in the F5-Cisco ISE Load Balancing Guide and in BRKSEC-3699 (Reference presentation) posted to CiscoLive.com.

View solution in original post

Content for Community-Ad