cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1012
Views
0
Helpful
3
Replies

ISE Guest Portal - SMS Notification flow

rdediana
Cisco Employee
Cisco Employee

Hello folks,

a couple questions regarding ISE SMS notification service, and, the traffic flows required to complete the transactions within a distributed deployment.


The design includes separate PAN and PSN nodes with respective HA primary / secondary roles running version 2.3 patch2


Questions:

1. Once the SMS gateway is configured, which node is responsible for initiating and completing the SMS transaction? PAN or PSN?

2. if multiple interfaces are configured on the respective ISE node, it is possible to configure an ip route (cli) to influence the selection of ISE node egress interface used to communicate with the SMS provider?


thanks.

Regan

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

It should be originated from PSN.  Are you not seeing this behavior?  You can verify by taking TCPDUMP off PSN interface.

Yes, the use of a static route can be used to influence the exit interface for external communications.  Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.

View solution in original post

3 Replies 3

kvenkata1
Cisco Employee
Cisco Employee

I will respond after I am able to locate the answer internally.

Craig Hyps
Level 10
Level 10

It should be originated from PSN.  Are you not seeing this behavior?  You can verify by taking TCPDUMP off PSN interface.

Yes, the use of a static route can be used to influence the exit interface for external communications.  Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.

thanks Craig. will test in the lab today.