Forum Discussion
Richard_Schmit_
Nimbostratus
Apr 22, 2013Load Balance Cisco ISE servers
Trying to load Balance several Cisco ISE servers. For persistence, Cisco recommends using Calling-Station-ID and Framed-IP-address...Session-ID is recommended if load balancer is capable of it. I h...
Richard_Schmit_
Nimbostratus
Apr 23, 2013THis is a new trun-up. Testing this week and next.
Couple of bullet points that are taken from the Cisco ACE configuration PDF....
• Load Balancers get listed as NADs in ISE so their test authentications may be answered.
• ISE uses the Layer 3 address to identify the NAD, not the NAS-IP-Address in the
RADIUS packet. This is a primary reason to avoid Source NAT (SNAT) for traffic sent to
VIP.
So the way I'm understanding it is that NADs or network access devices which are the end station send the request to the LTM’s. Once the packet hits the LTM, then the LTM becomes the NAD from the perspective of the ISE servers.
I don' think source persistence works because on the initial request the end device still doesn't have an IP address. The ISE servers determine who and what the client is, and then based on that assign the vlan and IP space etc.
I had never used the "Persist Attribute" setting in radius profile before. I see where that setting is, but where do you apply it once you create it?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
