cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
859
Views
0
Helpful
1
Replies

ise portal redirect workaround

Spyros Kasapis
Level 1
Level 1

Hello ,

 

according to this link

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117278-troubleshoot-ise-00.html#anc11

Scenario 3 - Destination Host is in Different VLAN, Exists, and is SVI 10 UP

 

 

We have the same implementation and the checkpoint firewall drops the request as spoofed or out of state . (The guest vlan and management are in different subnets). If we create an SVI of guest vlan everything works fine but we cannot create it in all the enterprise switches . Do you know any other workaround (we can disable inpection in firewall but not antispoofing) .

 

Thank you .

1 Reply 1

I think you should enable the TCP state bypass on the Checkpoint firewall to resolve this issue.