cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2358
Views
35
Helpful
8
Replies

ISE can support dynamic IP assignment for VPN remote access?

jewfcb001
Level 4
Level 4

Hi All, 

 

I see some post about ise cannot support dynamic ip assign . I believe ISE support only "framed-IP-Address attribute" for return to ASAv  VPN remote access. but i cannot find the official document ISE cannot support dynamic IP assignment . 

Please advise me 

 

 

8 Replies 8

@jewfcb001 you can configure ISE to send the DHCP scope to the ASA, using the following:

 

1.PNG

@Rob Ingram 

Hi Rob 

Thank you for your information . but i think from your information ,the information similar with DHCP Reley or not ? 

and I want cisco ise assign dynamic ip address pool to client with remote access VPN . 

 

 

@jewfcb001 That command is basically telling the ASA which DHCP scope to use when assigning an IP address.

 

If you just want ISE to tell the ASA which IP pool to use on the ASA, you can use the RADIUS AV below in an Authorisation Profile.

 

CVPN3000/ASA/PIX7x-Address-Pools=<NAME OF POOL CONFIGURED ON ASA>

 

Refer to ISE section of this guide (at the bottom) for detailed information

@Rob Ingram 

Thank you for you information . But If I want to assign POOL IP by ISE not assign via ASA or other firewall . Can I do it ?

@jewfcb001 if I understand correctly, then no, you cannot define an address pool on ISE.

 

You can use the 2 suggestions above, which dynamically instructs the ASA to use a pre-defined IP pool already configured on the ASA or which DHCP scope to use, which relies on a DHCP server configured with the scope.

 

The only other option I can think of is assigning static IP address per user, example.

@Rob Ingram 

 

Yes. You are correct . I believe ISE cannot assign IP POOL to client but I cannot find the official information . 

@jewfcb001 ISE is a AAA server it is not designed to host IP pools for VPN clients, I doubt you will find documentation for this.

 

The closest you will get is ISE can provide DHCP services for guest, this may work for you.

 

1.PNG

 

....but the best solution is to utilise the built functionality of the dedicated VPN device the users are connecting to.

Why pool? Framed-ip-address is same,

It return ip auth host can use it.