01-01-2022 01:44 PM
I'm tasting Dot1X / Posture / General RADIUS in my lab, and I want to have some clients with a private VLAN behind NAT, are there any considerations to keep in mind when I use ISE as the radius server?
Solved! Go to Solution.
01-03-2022 07:18 PM
There is nothing really specific required to handle clients behind NAT, but the profiling information ISE has for these clients may be off or partial. As long as the radius authentication being sent from the network device itself isn't natted, then you will handle it like regular endpoint authentication.
If the switch communicating with ISE is behind nat, then it's a whole different can of worms.
01-03-2022 07:18 PM
There is nothing really specific required to handle clients behind NAT, but the profiling information ISE has for these clients may be off or partial. As long as the radius authentication being sent from the network device itself isn't natted, then you will handle it like regular endpoint authentication.
If the switch communicating with ISE is behind nat, then it's a whole different can of worms.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide