07-10-2018 07:22 PM
Hello folks,
a couple questions regarding ISE SMS notification service, and, the traffic flows required to complete the transactions within a distributed deployment.
The design includes separate PAN and PSN nodes with respective HA primary / secondary roles running version 2.3 patch2
Questions:
1. Once the SMS gateway is configured, which node is responsible for initiating and completing the SMS transaction? PAN or PSN?
2. if multiple interfaces are configured on the respective ISE node, it is possible to configure an ip route (cli) to influence the selection of ISE node egress interface used to communicate with the SMS provider?
thanks.
Regan
Solved! Go to Solution.
07-11-2018 04:11 PM
It should be originated from PSN. Are you not seeing this behavior? You can verify by taking TCPDUMP off PSN interface.
Yes, the use of a static route can be used to influence the exit interface for external communications. Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.
07-11-2018 09:14 AM
I will respond after I am able to locate the answer internally.
07-11-2018 04:11 PM
It should be originated from PSN. Are you not seeing this behavior? You can verify by taking TCPDUMP off PSN interface.
Yes, the use of a static route can be used to influence the exit interface for external communications. Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.
07-12-2018 11:36 AM
thanks Craig. will test in the lab today.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide