08-19-2013 03:50 AM - edited 03-10-2019 08:47 PM
Trying to load Balance several Cisco ISE servers. For persistence, Cisco recommends using Calling-Station-ID and Framed-IP-address...Session-ID is recommended if load balancer is capable of it. I have documentation for the Cisco ACE, but using F5 LTM's. Assuming this has to be done with an I-Rule as none of these are available as a default. Not sue where to begin. I tried attaching the Cisco PDF, but not able for whatever reason.
08-27-2013 07:47 PM
Please also keep in mind that When using a Load-Balancer (anyone's) you must ensure a few things.
08-27-2013 09:36 PM
Mohana,
The link that Ravi is referencing is from a blog which is posted below -
https://supportforums.cisco.com/community/netpro/security/aaa/blog/2012/09/19/ise-and-load-balancing
You will need to set persistence or stickiness for the called-station-id since the ISE PSN generate radius state attributes for each client. If the session transitions from one psn to the next then this can cause a mess by dropped request and the load balancer marking psns dead.
I agree with you the loadbalancing scenario isnt well documented lets see if we can some help from Cisco and not links to general guides.
Tarik Admani
*Please rate helpful posts*
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide