05-14-2015 08:50 AM - edited 03-12-2019 05:45 PM
Greetings,
Q1: Is there any way to limit access to the ISE management functionality to a specific physical interface on the appliance?
Q2: If the answer to Q1 is no, I see that we can limit access to specific IP ranges. If we do this, does it apply to the CLI as well as the web gui?
Thanks.
05-14-2015 02:44 PM
Yes,it is how it works by default. Only gigabitethernet 0 can be used for management of ISE, other services like guest, can be moved to other interfaces.
05-15-2015 08:52 AM
That's good news, thank you.
05-20-2015 12:00 AM
Cisco ISE management is restricted to Gigabit Ethernet 0.
Cisco ISE Appliance Ports Reference
http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_c-ports.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide