08-07-2017 07:09 AM
Hi Experts,
How many IP addresses/subnets/ranges can be configured in each network device object? ACS has some limitation, so we need to create multiple network device objects to a large number of IP entries as the below screenshot. How many of those entries can be added into the IP address field in ISE v2.3?
Solved! Go to Solution.
08-07-2017 07:02 PM
Please clarify why needing many IP addresses here. ISE 2.3 also supports ranges on all octets.
For ISE, the limitation appears mainly on rendering. On ISE 2.3 standalone, I was able to import a NAD with as many as 100 addresses but rending not working until I reduced it to ~ 35 entries.
08-07-2017 05:35 PM
I asked the experts
08-07-2017 07:02 PM
Please clarify why needing many IP addresses here. ISE 2.3 also supports ranges on all octets.
For ISE, the limitation appears mainly on rendering. On ISE 2.3 standalone, I was able to import a NAD with as many as 100 addresses but rending not working until I reduced it to ~ 35 entries.
08-07-2017 10:12 PM
My customer runs a management network to provide management access to other major clients major networks, and ACS is used to authenticate users and authorise their access to those major network components for management purpose.
Each one of the customer may have network presence in one or more metro hubs and exchanges in one or more states in Australia, and each such site would have a subnet or even multiple small subnets given to the customer.
Therefore when we define a network device (in some way it can be treated as a group with a collection of management IP subnets and addresses to represent their network infrastructure), it may have 10, 20, or even more IP subnets configured. In ACS, for some large network device IP collection, we may need to split IP addresses into 3 or more network devices, each with customerA_network1, customerA_network2, and customerA_network3, and so on, because of the IP limitation in ACS for each network device
It’s not such a problem that customer will need to do this, but just like to know if similar limitation also happens in ISE, so my customer is aware of it and not treat it as a bug. Also when we continue to add new IP addresses into existing network device, the customer knows when to create a new network device because the current one can’t have any more IPs added in.
hope this use case makes sense in ISE deployment, today the customer is still using ACS and hoping to migrate to ISE v2.3
12-08-2017 04:38 AM
Hello,
Are there any limitations on the subnet mask that is supported?
My customer has been able to add a /24 range, and validated it successfully.
Adding a /16 range was accepted, but not working when validating with a NAD from that range.
Thanks.
12-09-2017 05:54 AM
I suggest they go to tac
12-09-2017 05:18 PM
I tried /16 in my own lab and it worked fine. We also have it in alpha working fine. FYI.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide