cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
511
Views
3
Helpful
2
Replies

ISE specific interface for Device Admin operation

Hi all;

As far as I know, ISE by default supports RADIUS-based traffic in all interfaces (interfaces other the Gig 0). I want to know that, is this rule also applies for TACACS traffic?

Thanks

1 Accepted Solution

Accepted Solutions

Hi @rezaalikhani 

ALL Interfaces can be configured with IP Addr.

RADIUS and TACACS+ can be performed on separate Interface, but listen on ANY Interface.

Guest/Sponsor/My Devices/BYOD Portals can be configured and restricted for specific Interfaces

ISE management is restricted to GigabitEthernet 0

 

Hope this helps !!!

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

It's the same case with TACACS, too, as far as I know; if you like, you can use a dedicated interface depending on deployment; make sure you have a high availability setup.

https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi @rezaalikhani 

ALL Interfaces can be configured with IP Addr.

RADIUS and TACACS+ can be performed on separate Interface, but listen on ANY Interface.

Guest/Sponsor/My Devices/BYOD Portals can be configured and restricted for specific Interfaces

ISE management is restricted to GigabitEthernet 0

 

Hope this helps !!!