ā08-05-2014 03:13 AM - edited ā03-10-2019 09:55 PM
Hi,
We've an ISE cluster of two ISE nodes.
The ISE guest server works fine on the primairy ISE node.
MAC address of the guest client is set in the map 'GuestDevices' after accepting the AUP policy.
The the ISE sents the COA and the client authenticates again and is punt in the guest vlan.
But when the primairy ISE is offline, I see the guest portal AUP page on the secondairy ISE node.
I can accept the AUP policy, and I get an error message.
On the secondairy ISE I see that the COA to the switch is sent, to clear the session to the primairy ISE....
But the COA request should ask to clear the session to the secondairy ISE ( the primairy ISE is offline ).
Should it be possible to configure the ISE guest functionality redundant in an ISE cluster?
/SB
ā08-05-2014 03:29 AM
The Guest portal can run on a node that assumes the Policy Services persona when the primary node with Administration persona is offline. However, it has the following restrictions:
ā¢Self registration is not allowed
ā¢Device Registration is not allowed
ā¢The AUP is shown at every login even if first login is selected
ā¢Change Password is not allowed and accounts are given access with the old password.
ā¢Maximum Failed Login is not be enforced
http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_guest_pol.html#wp1126706
ā08-05-2014 03:49 AM
Hi, we're running ISE version 1.2 patch 9.
The url you sent me is for ISE 1.0
I can't find this for ISE version 1.2, but it seems to be the same behavior.
Is this info also available for ISE version 1.2 ?
Regards,
SB
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide