05-26-2021 05:43 AM
Hi, am planning to shift my pxGrid service (Passive authentication for FMC) from one of my existing VM to new distributed appliance environment.
Setup:
My plan is to enable pxGrid service in one of the PSN node only.
My question as below:
- In my FMC, do I require to add my PAN/MNT? Or just the pxGrid node subscriber
- For ports requirement > link , do I need to enable port service for other nodes, even only one node using the pxGrid service (attached my firewall port requirement)
Solved! Go to Solution.
05-26-2021 12:30 PM
it is not required to be enabled on MNT (requires port 8910 communication with FMC), just PSN Pxgrid node.
Things to consider:
- Confirm version support between ISE / FMC
- You might consider having a second Pxgrid node for redundancy.
- Just follow the config guide and you should be fine.
05-26-2021 06:17 AM
For pxgrid with FMC, you will need to have 1 pxgrid controller (pxgrid node) and also MNT node communication to perform bulk downloads.
Ports need to be open for Pxgrid node and MNT only.
05-26-2021 06:24 AM - edited 05-26-2021 06:28 AM
Hi Irojaslo,
For pxGrid service enablement:
- If I were to enable on a PSN node, do primary & secondary MNT needs to enable the service?
For ports required:
- Do I need to include both primary & secondary MNT?
- Any best practice?
7 nodes in new environment
05-26-2021 12:30 PM
it is not required to be enabled on MNT (requires port 8910 communication with FMC), just PSN Pxgrid node.
Things to consider:
- Confirm version support between ISE / FMC
- You might consider having a second Pxgrid node for redundancy.
- Just follow the config guide and you should be fine.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide