
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-08-2018 07:40 AM
Hello Community,
In our Environment Currently running with ISE 2.1 with patch 1,3 & 5.
Our Company is planning to make ISE as DHCP server for providing 25K IP address with 100 subnets.
IS it feasible to configure for ISE as DHCP , if configured what will be impact (or) any future issue with ISE with DHCP Server.
is anyone applied this setup in their environment ?
Needful suggestion would be highly appreciated.
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-09-2018 05:23 AM
There is no general purpose dhcp service in ISE
Please look into other dhcp servers from Microsoft or Infoblox as an example

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2019 10:48 PM
https://community.cisco.com/t5/security-documents/ise-features-by-release/ta-p/3621656#toc-hId-155267693
Since 1.1 is real old please install latest recommended release 2.4 as fresh install, configure and evaluate. I wouldn’t recommend an upgrade unless critical to maintain user accounts
Things are so much different starting from scratch would be very beneficial.
You can always point ise back to itself if needing access to older system,

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-08-2018 08:27 AM
ISE is not a DHCP server.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-09-2018 05:13 AM
but still, if we want to enable DHCP on ISE
is it feasible for 25K IP address with more than 100 subnets ? what be the performance impact on ISE with future issues related with DHCP.
Does anyone have implemented this solution, if so what are the challenges you have faced in your network.
Thanks

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-09-2018 05:23 AM
There is no general purpose dhcp service in ISE
Please look into other dhcp servers from Microsoft or Infoblox as an example
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-09-2018 04:13 PM
To clarify a bit...
The DNS/DHCP server function in ISE is specific to Auth VLAN feature to support 3rd-party or other NADs that lack URL redirect support. As such, it will delve out IP addresses with a DNS server address that points to ISE itself to sinkhole your web traffic until auth is complete!
Next, the lease timers are deliberately set to low values to facilitate re-DHCP post auth and allow endpoint to get IP address in new access VLAN at which point the ISE DNS/DHCP server is no longer used, i.e. you must use an external DHCP server in access VLAN.
This is why you would not use the ISE DNS or DHCP server for any general use case.
Craig
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-15-2019 10:23 PM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2019 10:48 PM
https://community.cisco.com/t5/security-documents/ise-features-by-release/ta-p/3621656#toc-hId-155267693
Since 1.1 is real old please install latest recommended release 2.4 as fresh install, configure and evaluate. I wouldn’t recommend an upgrade unless critical to maintain user accounts
Things are so much different starting from scratch would be very beneficial.
You can always point ise back to itself if needing access to older system,

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-25-2020 08:27 PM
