cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2265
Views
10
Helpful
7
Replies

Profiler Feed Service - Which node downloads?

dcarrion
Level 1
Level 1

In a distributed ISE deployment, which node actually goes out to Cisco.com for the updates?  The PAN's in this deployment are firewalled off, but the PSN's are not, so do I need to modify my FW rules to allow the PAN's to get out?

Dan

1 Accepted Solution

Accepted Solutions

Hi Shiva,

 

It is clearly mentioned in diagram with port number, you can see that in right bottom of the diagram as cloud service.

 

Thanks,

Aravind

-Aravind

View solution in original post

7 Replies 7

I have this problem too. I am unable to find out from the Admin Guide and the ISE Port Reference whether PAN will download the ISE profiling and posture feed OR it is PSN which download it. There is no clear answer till now.

Cisco, please can you check on this asap ?

Hi Shiva,

 

PAN will take the feed from cisco.com/perfigo.com , you need to allow tcp/443 for posture updates & tcp/8443 for profiling feeds in your firewall.

Image 1.png

 

Otherwise you can configure a proxy server under Administration->System->Settings->Proxy which will take feed through proxy server

 

you can refer this document for all ports related queries: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23_chapter_0110.pdf

 

Hope that answers your query!

 

Thanks,

Aravind

-Aravind

Hi Aravind, thanks for your reply.

 

I know that the diagram mentions that it is PAN but there are no details of profiler/posture feed in ports used by PAN or PSN. That is where it confuses.

 

I am waiting for response from Cisco. I see no one replies often for these questions, waiting for answers.

 

Thanks.

Hi Shiva,

 

It is clearly mentioned in diagram with port number, you can see that in right bottom of the diagram as cloud service.

 

Thanks,

Aravind

-Aravind

 

Sorry for the typo.

 

I know that the diagram mentions that it is PAN but there are no details of profiler/posture feed in ports used by PAN or PSN in the tables mentioned in ISE Port Reference PDF. I am talking about the tables of ports used by Admin, PSN, MNT mentioned in the ISE port reference pdf where there is no mention of profiler/posture feed updates. That is where it confuses.

 

I have done enough research before posting this one and only waiting for response from Cisco.

 

Thanks

Aravind is correct that the primary ISE node initiates the out bound connections to the profiler feed server on its HTTPS on TCP 8443.

Aravind is correct that the primary ISE node initiates the out bound connections to the profiler feed server on its HTTPS on TCP 8443.