Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Is it possible to make the ISE guest server redundant ?

Hi,

We've an ISE cluster of two ISE nodes.

The ISE guest server works fine on the primairy ISE node.

MAC address of the guest client is set in the map 'GuestDevices' after accepting the AUP policy.

The the ISE sents the COA and the client authenticates again and is punt in the guest vlan.

But when the primairy ISE is offline, I see the guest portal AUP page on the secondairy ISE node.

I can accept the AUP policy, and I get an error message.

On the secondairy ISE I see that the COA to the switch is sent, to clear the session to the primairy ISE....

But the COA request should ask to clear the session to the secondairy ISE ( the primairy ISE is offline ).

Should it be possible to configure the ISE guest functionality redundant in an ISE cluster?

/SB

2 REPLIES
Cisco Employee

The Guest portal can run on a

The Guest portal can run on a node that assumes the Policy Services persona when the primary node with Administration persona is offline. However, it has the following restrictions:

Self registration is not allowed

Device Registration is not allowed

The AUP is shown at every login even if first login is selected

Change Password is not allowed and accounts are given access with the old password.

Maximum Failed Login is not be enforced

http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_guest_pol.html#wp1126706

New Member

Hi, we're running ISE version

Hi, we're running ISE version 1.2 patch 9.

The url you sent me is for ISE 1.0

I can't find this for ISE version 1.2, but it seems to be the same behavior.

Is this info also available  for ISE version 1.2 ?

Regards,

SB

78
Views
0
Helpful
2
Replies
CreatePlease login to create content