11-12-2018 05:30 AM
Hello,
I was wondering if I should point my Network Access Device's to our ISE PSNs profiler IP address or the IP address used during the initial ISE setup? The way I'm building out our ISE deployment is that I have 2 IP addresses assigned to our PSNs. One address is used for Web management as well as TACACS+ and the other is used for the profilers (HTTP, DHCP, etc.). When I configure RADIUS on the network devices, should I use the address TACACS+ is using, the address I'm using for profiling, or does it even matter?
Thanks!
Solved! Go to Solution.
11-12-2018 06:49 AM
11-12-2018 06:12 AM
11-12-2018 06:21 AM
Hello Surendra,
Got it. So this brings up another question...since it doesn't matter which address I use for RADIUS requests, I can then use both addresses on my NADs for each PSN as a form of redundancy to that specific node, right? In other words, if Gi0 on PSN1 goes down, it can still serve RADIUS requests because my NADs also have the address of Gi1 for that same PSN. Would I be somewhat correct?
11-12-2018 06:29 AM
11-12-2018 06:31 AM
Yeah but when you got other admins changing things around in a virtual environment or cabling new devices, things tend to happen and not in a good way. But it's good to know I can use ISE in this manner. Thanks so much for your feedback!
Terence
11-12-2018 06:49 AM
11-12-2018 06:49 AM
11-12-2018 06:55 AM
Thanks Jason,
My deployment will consist of two PAN/MnT nodes and two PSNs in which the PSNs are doing the profiling. I am specifying both PSNs for redundancy for our NADs and endpoint devices but also like the idea of using both IP addresses for redundancy to the same PSN. I'm still in the early stages of the deployment and ISE isn't fully into production; just using it for TACACS & VPN access but no wired or wireless dot1x as of yet.
Thanks for the reference links as well. I'll check them out.
11-12-2018 09:14 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide