cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1664
Views
0
Helpful
6
Replies

tcp/udp ports allowed across firewall between ISE nodes

cciesec2011
Level 3
Level 3

I have 2 ISE nodes version 2.6 patch 2.  ISE1 is the primary admin/MnT and PSN node that is behind a firewall interface.  ISE2 is the secondary admin/MnT node that is behind another firewall interface.  What TCP/UDP ports must be allowed across the firewall for the ISE nodes to be communicated with each other effectively.

 

TIA.

1 Accepted Solution

Accepted Solutions

Please do provide us what's wrong so we may update. if there is TAC case provide that so we can follow up. I would ask they open defect

View solution in original post

6 Replies 6

Hi,

Here is the port reference for ISE.

 

HTH

do you have first hand experience on specific ports and protocols?

What is your specific question or concern?  The reference lays out all of the communication requirements for the various node types and features.


@Colby LeMaire wrote:

What is your specific question or concern?  The reference lays out all of the communication requirements for the various node types and features.


Because the documentation is either wrong or incomplete for version 2.6 patch 2.  I opened a TAC case with Cisco and even the TAC engineer is not very clear on the ports and protocols that have to be opened on the firewalls for it to work properly.  The TAC engineer told me one thing and I am seeing something else.

If you have packet captures showing that the documentation is incomplete or wrong, then provide that to TAC and have them open a documentation bug.  Or post your information here to the community so the folks in the BU can review and verify.

Please do provide us what's wrong so we may update. if there is TAC case provide that so we can follow up. I would ask they open defect