ISE and firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2013 02:39 PM - edited 03-10-2019 08:14 PM
I have a Primary ISE node (primary admin/monitoring/policy) sitting in network 192.168.1.0/24 and the Secondary ISE node (secondary admin/monitoring/policy) sitting in network 192.168.2.0/24. There is a firewall sitting between these two networks.
What TCP and UDP ports do I need to open on the firewalls so that these two nodes can communicate and sync with each other? I AM ONLY INTERESTED IN THE TRAFFICS BETWEEN THESE TWO NODES and not other traffics to else where.
I've read through the documentation and it seems that I only need a couple of tcp and udp ports for this.
Any comments?
Thank you in advance.
david
- Labels:
-
AAA

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-29-2013 06:09 AM
David,
AFAIU minimum of TCP/443 and TCP/1521 (and ICMP for hearbeat).
http://www.cisco.com/en/US/partner/docs/security/ise/1.1/installation_guide/ise_app_e-ports.html
M.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-02-2013 05:19 AM
I would suggest you to use any sniffer like wireshark to look into the packet flow going on between those two nodes and anlayze the traffic flow. Accordingly open the required TCP and UDP ports on your firewall.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-02-2013 07:49 AM
Hi,
Take a look at Figure 23 in this document: http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_50_ise_deployment_tg.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-21-2013 03:48 AM
Agree with Philip:
Review the below link:
