09-02-2019 10:45 AM
I have 2 ISE nodes version 2.6 patch 2. ISE1 is the primary admin/MnT and PSN node that is behind a firewall interface. ISE2 is the secondary admin/MnT node that is behind another firewall interface. What TCP/UDP ports must be allowed across the firewall for the ISE nodes to be communicated with each other effectively.
TIA.
Solved! Go to Solution.
09-03-2019 10:58 AM
09-02-2019 10:53 AM
09-02-2019 11:15 AM
do you have first hand experience on specific ports and protocols?
09-02-2019 11:59 AM
What is your specific question or concern? The reference lays out all of the communication requirements for the various node types and features.
09-03-2019 02:36 AM
@Colby LeMaire wrote:What is your specific question or concern? The reference lays out all of the communication requirements for the various node types and features.
Because the documentation is either wrong or incomplete for version 2.6 patch 2. I opened a TAC case with Cisco and even the TAC engineer is not very clear on the ports and protocols that have to be opened on the firewalls for it to work properly. The TAC engineer told me one thing and I am seeing something else.
09-03-2019 10:07 AM
If you have packet captures showing that the documentation is incomplete or wrong, then provide that to TAC and have them open a documentation bug. Or post your information here to the community so the folks in the BU can review and verify.
09-03-2019 10:58 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide