cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
316
Views
0
Helpful
2
Replies

Is it possible to make the ISE guest server redundant ?

s.both
Level 1
Level 1

Hi,

We've an ISE cluster of two ISE nodes.

The ISE guest server works fine on the primairy ISE node.

MAC address of the guest client is set in the map 'GuestDevices' after accepting the AUP policy.

The the ISE sents the COA and the client authenticates again and is punt in the guest vlan.

But when the primairy ISE is offline, I see the guest portal AUP page on the secondairy ISE node.

I can accept the AUP policy, and I get an error message.

On the secondairy ISE I see that the COA to the switch is sent, to clear the session to the primairy ISE....

But the COA request should ask to clear the session to the secondairy ISE ( the primairy ISE is offline ).

Should it be possible to configure the ISE guest functionality redundant in an ISE cluster?

/SB

2 Replies 2

mohanak
Cisco Employee
Cisco Employee

The Guest portal can run on a node that assumes the Policy Services persona when the primary node with Administration persona is offline. However, it has the following restrictions:

ā€¢Self registration is not allowed

ā€¢Device Registration is not allowed

ā€¢The AUP is shown at every login even if first login is selected

ā€¢Change Password is not allowed and accounts are given access with the old password.

ā€¢Maximum Failed Login is not be enforced

http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_guest_pol.html#wp1126706

Hi, we're running ISE version 1.2 patch 9.

The url you sent me is for ISE 1.0

I can't find this for ISE version 1.2, but it seems to be the same behavior.

Is this info also available  for ISE version 1.2 ?

Regards,

SB

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: