06-14-2017 01:52 PM - edited 03-11-2019 12:47 AM
In a distributed ISE deployment, which node actually goes out to Cisco.com for the updates? The PAN's in this deployment are firewalled off, but the PSN's are not, so do I need to modify my FW rules to allow the PAN's to get out?
Dan
Solved! Go to Solution.
10-18-2018 10:49 PM
Hi Shiva,
It is clearly mentioned in diagram with port number, you can see that in right bottom of the diagram as cloud service.
Thanks,
Aravind
10-18-2018 09:24 AM
I have this problem too. I am unable to find out from the Admin Guide and the ISE Port Reference whether PAN will download the ISE profiling and posture feed OR it is PSN which download it. There is no clear answer till now.
Cisco, please can you check on this asap ?
10-18-2018 10:25 AM
Hi Shiva,
PAN will take the feed from cisco.com/perfigo.com , you need to allow tcp/443 for posture updates & tcp/8443 for profiling feeds in your firewall.
Otherwise you can configure a proxy server under Administration->System->Settings->Proxy which will take feed through proxy server
you can refer this document for all ports related queries: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23_chapter_0110.pdf
Hope that answers your query!
Thanks,
Aravind
10-18-2018 10:27 PM - edited 10-18-2018 10:30 PM
Hi Aravind, thanks for your reply.
I know that the diagram mentions that it is PAN but there are no details of profiler/posture feed in ports used by PAN or PSN. That is where it confuses.
I am waiting for response from Cisco. I see no one replies often for these questions, waiting for answers.
Thanks.
10-18-2018 10:49 PM
Hi Shiva,
It is clearly mentioned in diagram with port number, you can see that in right bottom of the diagram as cloud service.
Thanks,
Aravind
10-18-2018 10:57 PM
Sorry for the typo.
I know that the diagram mentions that it is PAN but there are no details of profiler/posture feed in ports used by PAN or PSN in the tables mentioned in ISE Port Reference PDF. I am talking about the tables of ports used by Admin, PSN, MNT mentioned in the ISE port reference pdf where there is no mention of profiler/posture feed updates. That is where it confuses.
I have done enough research before posting this one and only waiting for response from Cisco.
Thanks
10-21-2018 05:08 AM
Aravind is correct that the primary ISE node initiates the out bound connections to the profiler feed server on its HTTPS on TCP 8443.
10-21-2018 05:08 AM
Aravind is correct that the primary ISE node initiates the out bound connections to the profiler feed server on its HTTPS on TCP 8443.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide