cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
4
Replies

securing ise

susim
Level 3
Level 3

Hi , 

I am redirecting (url redirecting )  wireless clients to ise .The problem is i have opened port 80 ,443 and 8443 . So the users can even connect to the admin (web ) console to the ise  . How can i avoid these ?
Thanks

4 Replies 4

jan.nielsen
Level 7
Level 7

Only 8443 is needed for guest access with ISE, no need to open 80 or 443 towards ISE. Furthermore, if you are concerned about the sponsor portal (which also runs on 8443), you can select another port for it, and even another interface in ISE.
 

Hi,

you can select another port for it, and " even another interface in ISE."

you mean if the client is in 10.0.10.x network ,i can assign ip from this network (eg: 10.0.10.1)

to an interface on ise ? 

Thanks

 

Yes, you could do that, and then have the guest services running on that interface. Just remember it can't be used as a router, so don't try to set it as default gateway or anything like that.

jj27
Spotlight
Spotlight

Jan is correct.  Furthermore, you can also configure ISE admin access to be restricted to specific IP addresses or subnets.  You can do that by configuring it at:  Administration->Admin Access->Settings->IP Access.