cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4389
Views
0
Helpful
2
Replies

ISE Smart Licensing Proxy Connection

gaigl
Level 3
Level 3

Hello,

 

I want to upgrade a Test-ISE from 2.7 to 3.0 and I think first I need to convert to Smart Licensing, this is right?

when I want to register to Smart License I can use a proxy, but the proxy address is http://webproxy.company.int:8080 and if I want to register with HTTPS Proxy the ISE uses the address https://webproxy.company.int:8080/ddce/services/DDCEService and I get an connection error.

On the Proxy-Log I see an connection attempt to https://tools.cisco.com, which is allowed, but nothing else.

 

Any Idea's where to look for?

A direct connection through the firewall is no option, because on the firewall I can only establish connections to IP Adresses, and I think, this will change frequently

1 Accepted Solution

Accepted Solutions

gaigl
Level 3
Level 3

thank you, finally I managed it, there was a certificate for the proxy missing. ssl.interception was already disabled for cisco.com

View solution in original post

2 Replies 2

marce1000
VIP
VIP

   >I want to upgrade a Test-ISE from 2.7 to 3.0 and I think first I need to convert to Smart Licensing, this is right? 

   Yes. take note of the FAQ below and or look and search for 'Smart Licensing' to get sufficient info's

          https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/qa-c67-744190.html

 

                          >I experience problems when using Smart Licensing through a proxy 

  Ref : https://www.cisco.com/c/en/us/support/docs/switches/catalyst-9500-series-switches/214484-cisco-smart-licensing-troubleshooting.html

 >...

  FYI : 

  • Smart Licensing does not support HTTPS Proxy SSL certificate interception by default when using 3rd party proxies for the HTTPS Proxy method. To support this feature, you can either disable SSL interception on the Proxy, or manually import the certification sent from the Proxy.


-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

gaigl
Level 3
Level 3

thank you, finally I managed it, there was a certificate for the proxy missing. ssl.interception was already disabled for cisco.com

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: