HI Marvin,
Does that mean default management port will be used just for the initial configuration ?
later on, we could use one of 10 Gig ports to access FMC 4000 and using the same port all the Firepower and FTD devices communicating with FMC.
Can we able to configure port-channel on 10 Gig ports for FMC ? I am asking this as I Can see it has multiple 10 gig ports on it.
Thanks
Prashant
... View more
Here is my understanding , if someone would like to comment and confim if this is correct
Use case 1 :
authentication order mab dot1x
authentication priority dot1x mab
Result- first client will do MAB ( if this passed ) then will do the dot1x. If MAB auth failed then also do the dot1x. Negative side of this is that each and every device has to go through MAB process- overhead on ISE . if DOT1x is not successful it will get the policy as configured for MAB.
Use Case 2-
authentication order mab dot1x
authentication priority mab Dot1x
MAB failed , it will go to Dot1x
MAB passed- it will not go to DOT1x.
Use Case 3-
authentication order dot1x mab
authentication priority mab Dot1x
End-point will do Dot1x, will only go to MAB if DOT1x Fails.
... View more
Can someone out here please explain the meaning of below
interface <interface_number>
authentication order mab dot1x
authentication priority dot1x mab
what is the real-time use of order and priority commands ?
Is it mandatory to have priority command ?
Please give some real-life exmaples
... View more
With ISE PRoxy how CoA works ?
here is the setup :
Radius server >> ISE AS a radius proxy >>> Network device >> User
Normally ISE initiate the CoA to the NAD , however in this case can external radius device issue a CoA to the ISE ( which is somehow acting as a radius client ).
Anyone has done this and would like to advise ? I can not see any docs explaning this setup.
... View more
Hello guys,
I need to provide hotpsot internet for my guests , we would like to use ISE for policy management .
we have 4 PSNs located behind the F5 LB.
Guest are using the DMZ DHCP/DNS services.
Anchor controller is in DMZ.
Appreciate if someone out here please clarify below concerns :-
1- on Pre-auth ACL ( redirect ACL) at WLC do i need to just allow f5 VIP or F5 VIP + IPs of 4 PSNs , this access would be provided at TCP port 443 only ?
2- once client will go the guest portal where they just need to go through AUP before getting connected to the Internet, we want they should see URL on their browser something like "guestinternet.com" not the PSN IP address. Can it be done ?
3- We also like to install public CA signed certificate so that guest won'e be getting any certificate issues, Please advise if we just need certificate for 4 PSN nodes ?
We would like to order a single certificate having multiple SAN fileds , we want to add 4 PSNs and 2 Admin nodes as a part of SAN field on this certificate.
ISE is running version 1.3.
Thanks,
Prashant
... View more
Hello Team,
Hoping someone would pleas help me here :
I have ISE running in the production network , I have 4 PSNs, 2 MNT and 2 admin nodes.
Now we are in the process of deploying guest ( hotspot ).
Please note all 4 PSNs are located behing the f5 Load balancer.
Can you please advise on below :-
1- on Pre-auth ACL that we need to configure for hotspot can we have just access opened for F5 VIP not to PSNs ?
2- we also need to install public CA certificate to avoid any certificate error when guest will redirect to the AUP portal, for this can we have one certificate having SAN fields as 4 PSNS node and 2 admin nodes ? while generating CSR i need to select certificate is for portal ??
Thanks in advance for your help
... View more
Hello Guys,
Can someone please help me with below ISE queries ?
1- ISE is in the production network, however now we are in the position to enable guest SSID hence for that we need to have public CA sign certificate installed on PSNs. I have 4 PSNs, 2 MNT and 2 admin nodes, I would like to know if its ok to install this certifcate just on PSNs and Admin nodes, I Can ask for a certificate having multiple san fields ( PSNs and admin portals urls ) . if I proceed with this one , will it cause any issues in communciation between different nodes spically between MNT and other nodes as MNT is having different certs.
2- Any one has deployed ISE as a radius proxy ?
Thanks for help.
... View more
Hey Guys,
I have to implement the same solution. I understand we need to configure the authentication policy that would match field like SSID and domain name ( @cisco.com for example and if this condition satisfy then ISE will redirect this traffic to the external proxy server.
I am wondering, if we also need to configure any authorization policy to achieve this ?
Can you please confirm what authorization policy do you have for your setup ?
Thanks in advance for your reply.
... View more
we are in the process of deploying hotspot for our guests and we don't want that they should face any certificate error while redirecting to the ise portal.
Please help me to understand to process of importing public CA Certs to it. We have around 6 PSNs located behind F5.
thankd
please advise if this change requires any downtime .
tthanks
... View more
Hello Team,
ISE is running with code 1.3, I want to use this as a radius proxy for one of our clients.
I have already added client AD server as an external radius server in the ISE. There are two radius servers.
client wants to have policies configured in below manner-
Group A of AD sevrer ( radius server ) should be the part of vlan 10.
Group B of AD server ( radius server ) should be the part of vlan 20.
Can someone please confirm how authentication and authorixzation policies will look like ?
if anyone has deployed this use case ?
Thanks in advance.
... View more
Hello Guys,
I have 2 ISE nodes acting in all 3 personas, they are not located behind any load balancer devices. I would like to know if I have to configure authorization and authentication policy for both of nodes?
In other word what would be configuration ( policies) when ISE is not located behind any load balancer device ?
Thanks,
Prashant
... View more
Thanks Marvin,hence it must not be a good idea to rely on the base license for a production network.
As it can lead to some unexpected results. I will be buying license that can accommodate new 5 contexts.
... View more
Hello Team,
we have two ASA 5585-x running in cluster, I would like to know how many contexts we can create ?
if we are able to create total 4 contexts ( default with a base license ) then what would happen if one of the cluster member is down leaving just one active member in the cluster. will still 4 contexts would be liver and serving the traffic?
did anyone experience this , I would like to know more based on the experience. I didn't find any cisco doco explaining the same.
Questions :
What happens when one unit experiences outage?
Does the surviving unit still have 4 contexts and if so for how long?
Thanks,
Prashant
... View more