I have a requirement for Guest Internet access for the visitors. Persently we have deployed a Global Headend router which has the infra for Guest user DNS and AAA servers connected with it.
Also for other countries we have the Local Headend router and tailend routers.
Prsently we have created 2 VPN tunnel interfaces on the tailend routers. One will connect to local headend & other will connect to global headend.
We have created the offset list to filter only DNS and AAA traffic to global headend and after successful authentication the internet traffic will pass through Local headend.
Now we have come across a situation for deploying tailend routers which is large numbers in size. I have got an idea instead of having the vpn tunnel pointed between tailend routers to global headend router. We can have 1 tunnel created on Local headend and Global headend and all tailend will have only one vpn tunnel pointed to only Local headend. But i need to configure Local headend to forward the AAA and DNS traffic for all the requests come from tailend routers. DNS and AAA traffic should go from one tunnel to other.
i.e. Tailend <------- GRE Tunnel -------->Local Headend <--------- GRE Tunnel ----------->Global Headend
I have attached the diagram of my requirement.
If i make like the proposed design (Attached ). We can avoid creating multiple tunnels in the infra. 1 master tunnel between Local head end and Global Headend will server DNS and AAA for all the tailends connected to the Local headend.
We are excited to announce the opening of the ISE Beta community for the Cisco Identity Services Engine (ISE) 2.5 Beta for everyone that is a member of the Cisco Customer Connection Program (CCP)! The ISE 2.5 Beta is scheduled to run from Se...
ISE 2.2 Patch 10 has been released at ISE 2.2.0 Software Download since 2018-Sep-18, with the filename ise-patchbundle-184.108.40.2060-Patch10-18091119.SPA.x86_64.tar.gz.
For more info, please read Resolved Issues in Cisco ISE Version 220.127.116.110—Cumulative ...
ISE 2.3 Patch 5 has been released at ISE 2.3.0 Software Download since 2018-Sep-17, with the filename ise-patchbundle-18.104.22.1688-Patch5-18082702.SPA.x86_64.tar.gz.
For more info, please read Resolved Caveats in Cisco ISE Version 22.214.171.1248—Cumulative P...
I recently ran into an issue on ISE 2.3 Patch 5 when trying to modify a Hotspot Guest Portal that had been created in the ISE Portal Builder.
The support people with the ISEPB team gave me the answer, so I thought I'd save someone a...
The Security team is pleased to announce the Cisco Firepower Threat Defense 6.2.3 Attack Lab v1.2, available in all datacenters.
The lab is aimed at technical decision makers, security engineers and CSOs with an interest in security technology. Th...