06-13-2015 11:21 AM - edited 03-10-2019 10:48 PM
Documentation and books refer to allowing TCP/UDP ports 8905 and 8909 to the ISE servers in the AGENT-REDIRECT ACLs to make sure NAC agent can be prvisioned, be controlled by ISE and allow keepalive traffic. My question is if this all applies only to the NAC agent or if it applies to the AnyConnect Posture module as well, I couldn't have seemed to find this information anywhere. Are 8905 and 8909 ports still used in with:
- AnyConnect provisioning ?
- NSP provisioning ?
- AnyConnect posture module communication and keep alives ?
If not using NAC agent, would it be enough to only include port 8443 to ISE PSN(s) IPs?
Solved! Go to Solution.
10-21-2018 03:13 AM
Some documents show 8909 isn’t used in ise 2.0+
06-18-2015 03:14 AM
you will be still needing 8905 8909 with anyconnect
06-18-2015 12:31 PM
Thank you!
10-21-2018 03:13 AM
Some documents show 8909 isn’t used in ise 2.0+
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide