- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 08:00 AM
Hi,
I have eth0 configured for Radius and eth1 configured for Guest Portal access. The defualt gateway is configured for the same subnet as eth0. Eth1 is configured with and IP in the Guest subnet and I have configured an ip route for this subnet.
My problem is that I cant ping IP of eth1 from an Guest device (on the same subnet) but its no problem to ping from ISE to the same laptop. Does ISE block traffic on eth1 per default?
Solved! Go to Solution.
- Labels:
-
AAA
-
Guest
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 09:27 AM
A bug search reveals this - CSCvz93230 Guest portal does not load if hosted on a different interface from Gig0 but it's apparently resolved in 2.7 p7 and related to accessing the portal, nothing mentioned about no ping response.
Perhaps log a call with TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 10:24 AM
Please check below pointer on ISE:
- Are you able to reach the default gateway of eth1 from ISE?
- "show interface" output from ISE. Check the status of eth1 and also check if RX and TX counters are increasing when pings fail.
- While pinging eth1 from a PC, take pcap on the problematic PSN on eth1.
This should give some idea.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 08:16 AM - edited 05-25-2023 08:23 AM
@pontusd from ISE CLI create default route via the gateway the eth1 interface is connected to using the ip route command, Guest portal traffic will be routed via this next hop. RADIUS/Mgmt traffic will be routed via the eth0 default gateway IP address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 08:27 AM
As I wrote in my text. I have already configured an ip route for the guest subnet with the gateway of eth1.
Still not working
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 08:57 AM
Sorry, quite right I misread that. Last time I setup guest on a different interface, there were no settings on ISE restricting this communication. What ISE version and patch are you running?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 09:18 AM
ISE 2.7 Patch 9
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 09:27 AM
A bug search reveals this - CSCvz93230 Guest portal does not load if hosted on a different interface from Gig0 but it's apparently resolved in 2.7 p7 and related to accessing the portal, nothing mentioned about no ping response.
Perhaps log a call with TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-25-2023 10:24 AM
Please check below pointer on ISE:
- Are you able to reach the default gateway of eth1 from ISE?
- "show interface" output from ISE. Check the status of eth1 and also check if RX and TX counters are increasing when pings fail.
- While pinging eth1 from a PC, take pcap on the problematic PSN on eth1.
This should give some idea.
