07-10-2018 07:22 PM
Hello folks,
a couple questions regarding ISE SMS notification service, and, the traffic flows required to complete the transactions within a distributed deployment.
The design includes separate PAN and PSN nodes with respective HA primary / secondary roles running version 2.3 patch2
Questions:
1. Once the SMS gateway is configured, which node is responsible for initiating and completing the SMS transaction? PAN or PSN?
2. if multiple interfaces are configured on the respective ISE node, it is possible to configure an ip route (cli) to influence the selection of ISE node egress interface used to communicate with the SMS provider?
thanks.
Regan
Solved! Go to Solution.
07-11-2018 04:11 PM
It should be originated from PSN. Are you not seeing this behavior? You can verify by taking TCPDUMP off PSN interface.
Yes, the use of a static route can be used to influence the exit interface for external communications. Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.
07-11-2018 09:14 AM
I will respond after I am able to locate the answer internally.
07-11-2018 04:11 PM
It should be originated from PSN. Are you not seeing this behavior? You can verify by taking TCPDUMP off PSN interface.
Yes, the use of a static route can be used to influence the exit interface for external communications. Some management traffic like AD or inter-node communications is restricted to GE0, but quick test with TCPDUMP (or check source IP of traffic) could verify if that is the case for email/sms.
07-12-2018 11:36 AM
thanks Craig. will test in the lab today.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: