cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2490
Views
5
Helpful
4
Replies

ISE and firewalls

david.tran
Level 4
Level 4

I have a Primary ISE node  (primary admin/monitoring/policy) sitting in network 192.168.1.0/24 and the Secondary ISE node (secondary admin/monitoring/policy) sitting in network 192.168.2.0/24.  There is a firewall sitting between these two networks.

What TCP and UDP ports do I need to open on the firewalls so that these two nodes can communicate and sync with each other?  I AM ONLY INTERESTED IN THE TRAFFICS BETWEEN THESE TWO NODES and not other traffics to else where.

I've read through the documentation and it seems that I only need a couple of tcp and udp ports for this.

Any comments?

Thank you  in advance.

david

4 Replies 4

Marcin Latosiewicz
Cisco Employee
Cisco Employee

David,

AFAIU minimum of TCP/443 and TCP/1521  (and ICMP for hearbeat).

http://www.cisco.com/en/US/partner/docs/security/ise/1.1/installation_guide/ise_app_e-ports.html

M.

mojuneja
Level 1
Level 1

I would suggest you to use any sniffer like wireshark to look into the  packet flow going on between those two nodes and anlayze the traffic  flow. Accordingly open the required TCP and UDP ports on your firewall.