cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2503
Views
2
Helpful
5
Replies

ISE Guest Portal over NAT

iurikura
Cisco Employee
Cisco Employee

Hi,

Does ISE support accessing guest portal/sponsor portals over NAT ?

If Yes, could you please let me know any other design concens?

Thank you,

Itaru

2 Accepted Solutions

Accepted Solutions

Paul is correct.  There is no "official" ISE document where we declare support for NAT, but I have been publishing this setup for a few years now and have yet to hear any reported issues.  A key requirement for multi-interface setup is to set the interface alias using the 'ip host' command and to configure multi-default routing on PSN.  This allows traffic received on a given interface to be sent back out the same interface.   If need more details, I cover this in hidden slides of reference presentation in BRKSEC-3699 (available on ciscolive.com). 

/Craig

View solution in original post

There is no effort from a technical standpoint. Would recommend you reach out to the ISE product managers for support request if this is critical to you.

View solution in original post

5 Replies 5

paul
Level 10
Level 10

The guest portal is just an SSL call to a customer port (default is 8443).  There is no issue doing NAT in the path.  The source and destination can both be NATted.  The users's session information for the guest portal is contained as a variable in the URL the user gets redirected to.

It is very common to have completely isolated guest networks where we have to bring the guest portal traffic over the Internet to NAT IPs on the FW that get NATted to the PSNs.

Paul is correct.  There is no "official" ISE document where we declare support for NAT, but I have been publishing this setup for a few years now and have yet to hear any reported issues.  A key requirement for multi-interface setup is to set the interface alias using the 'ip host' command and to configure multi-default routing on PSN.  This allows traffic received on a given interface to be sent back out the same interface.   If need more details, I cover this in hidden slides of reference presentation in BRKSEC-3699 (available on ciscolive.com). 

/Craig

Thank you Paul, and Creig.

I understood.

Best regards,

Itaru

Hi Craig,

 

I know it's been some time from this post, but do we have any plans for Cisco TAC to officially support NAT configurations to access ISE Guest portals?

 

Thanks,

Oriol

There is no effort from a technical standpoint. Would recommend you reach out to the ISE product managers for support request if this is critical to you.