User Info

Welcome, Guest. Please login or register.
Did you miss your activation email?

Recent Posts

Pages: [1] 2 3 ... 10
Security / Re: EAP-FAST along with posture
« Last post by MC on April 02, 2019, 09:29:34 PM »
If you switch to native supplicant, does everything work the way it should?
Security / EAP-FAST along with posture
« Last post by ansar471 on March 31, 2019, 01:08:22 AM »

I am trying to authenticate my domain PC's/users with ISE and am using Anyconnect 4.2 with eap-fast user and machine authentication.

Everything was working with window 7 until i re-image two nodes from 1.4 to 2.2 and restore ISE configs. I have window 7 which is in process to upgrade to window 10.

1. After signing out window 10 machine authentication is happening and getting right result but after sign in with domain user posture is not working after looping its saying no policy server found. For it to work i have to click on NAM profile once more to re authenticate and in that case its starting its posture check.

2. Some machines are not even authenticating even i did restart, sign out. No session is showing on switch-port.
3. Some machine on authentication getting IPV6 logo only because we are not using IPv6 in the environment.
Security / Re: ISE 2.1 self signed certificates - Renew
« Last post by MC on March 09, 2019, 11:53:07 AM »
When you make changes to the cert, ISE service  always need to be restarted. Although you should be prompted that it will happen automatically, if you weren't, you might want to try to restart manually. But before you do that, try to clear browser cache to make sure the copy of cert you see was the browser cache copy.
Routing and Switching / Re: SDA question (On behalf of Tayo)
« Last post by MC on March 09, 2019, 11:49:12 AM »
Actually no. The purpose of LAN automation is that you do not need to perform any config on the device. In fact, the switch cannot have any config on it for the auto-provisioning to work. A brand new switch will get info from the seed switch DHCP server, automatically added to DNAC, and DNAC will push out the rest of config.
Routing and Switching / Re: SDWAN Demo License
« Last post by MC on March 09, 2019, 11:44:19 AM »
vManage does not come with any license be default. For lab use, you might be able to get a lab S/N file from your Cisco contact but it might be locked down to only organization name.
Security / ISE 2.1 self signed certificates - Renew
« Last post by Kojot on February 27, 2019, 09:31:14 AM »
hi all!

I do not find anything in any manulas regarding certificate on ISE server and renew option in self-signed cert(only import the new one is described). Currently I do not use  any internal or external CA. current self-signed cert will be not valid in few weeks and I would like to extend it for next year. When I did a change and put in renew field 1 year - I see that inside system certifcates the valid date is changed .the same after export and import that new one to Trusted certicates store on ISE Server. but when I logged in i see that in browser old certificates still exist. Is it neccessary to restart the ISE application ?
Ise didnt restart after i save certificate with new extended Valid date.
I have a distributed deployment 2xAdmin 2 x monitor 2x PSN

thx for help !!
Routing and Switching / SDWAN Demo License
« Last post by nareh84 on February 13, 2019, 03:48:43 PM »

I want to deploy and practice SDWAN viptela in my home lab using vedge cloud vm. i want to know when we install vManage, does it by default comes with particular number of vedge cloud vm demo license or not. Also is there a way to get demo license. i tried to contact Cisco AM but he told that demo license is not available and we have to get NFR.


Routing and Switching / Re: SDA question (On behalf of Tayo)
« Last post by TFashy on February 04, 2019, 10:16:44 PM »
Thanks for posting this on my behalf.

Is there a place for initial lab configurations?

Because if I understand you correctly, since all that was initially configured on BC2 was default routing, SNMP and local username/password we need to configure the same (all three) on other fabric members to be discovered and provisioned? And that includes pair border and edge switches.
Routing and Switching / Re: SDA question (On behalf of Tayo)
« Last post by Administrator on February 04, 2019, 08:51:38 PM »
When you use LAN automation to bring up the fabric underlay, all switches should be treated the same way. Only once the fabric underlay is up and all devices are added to DNAC, you then start provisioning fabric overlay and assign device role. The DHCP server device uses for initial communication is configured on the seed switch by DNAC so there is no need for external DHCP server. This is demonstrated in RS0118 video.
Routing and Switching / SDA question (On behalf of Tayo)
« Last post by Administrator on February 04, 2019, 08:47:37 PM »
I am trying to bring up fabric using a single seed border switch and CDP, what do I need configured on the second border switch and edge switches? 2nd is, do I need and exter DHCP server for discovery? Issue is I only see the seed switch.
Pages: [1] 2 3 ... 10
SimplePortal 2.3.5 © 2008-2012, SimplePortal