08-23-2015 07:48 AM - edited 03-10-2019 10:59 PM
Hi ,
I am redirecting (url redirecting ) wireless clients to ise .The problem is i have opened port 80 ,443 and 8443 . So the users can even connect to the admin (web ) console to the ise . How can i avoid these ?
Thanks
08-23-2015 09:45 AM
Only 8443 is needed for guest access with ISE, no need to open 80 or 443 towards ISE. Furthermore, if you are concerned about the sponsor portal (which also runs on 8443), you can select another port for it, and even another interface in ISE.
08-23-2015 08:46 PM
Hi,
you can select another port for it, and " even another interface in ISE."
you mean if the client is in 10.0.10.x network ,i can assign ip from this network (eg: 10.0.10.1)
to an interface on ise ?
Thanks
08-24-2015 07:45 AM
Yes, you could do that, and then have the guest services running on that interface. Just remember it can't be used as a router, so don't try to set it as default gateway or anything like that.
08-23-2015 07:09 PM
Jan is correct. Furthermore, you can also configure ISE admin access to be restricted to specific IP addresses or subnets. You can do that by configuring it at: Administration->Admin Access->Settings->IP Access.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide