ISE behind the load balancer

I have a question about ISE profiling of the servers that are placed behind a load balancer:

If you have an ISE environment where computers and users are be authenticated and restricted access Machine (MAR) is enabled (so that users can authenticate only on a machine already authenticated), the ISE servers up-to-date with all authentications of succesfull computer manipulated by other servers in the ISE?

For example:

There are 2 aircraft of ISE (ISE01 and ISE02) behind a load balancer.

A user starts the computer and the computer authentication is managed by ISE01 (and the authentication is successful). For the moment, that the user logs on to this computer, the load balancer selects ISE02 to authenticate the user.

ISE02 will be aware that the computer has been already properly authenticated on ISE01, so that users are able to connect? Or she refuses authentication of the user, because he thinks that the computer is not (yet) authenticated and Machine Access Restrictions is enabled?

Kind regards

Bert

ISE servers are aware of all authentications of succesfull computer manipulated by other servers in the ISE?

=> N°

they are independent servers that replicate that configuration.

If a user must always authenticate with the same ISE.

In addition, a load balancer kills profiling since profiling requires you to cover a portion of the traffic at the ISE

Tags: Cisco Security

Similar Questions

  • LiveCycle servers behind a load balancer.

    Hello everyone.

    We have livecycle ARE set up behind a load balancer (F5 BigIP). We have problems with the JMS queues. We are able to connect to the administration console make changes, etc., and the product seems to work very well until the JMS queues are used.

    We are only ports 8080 load balancing and nothing else. So I'm wondering if we need to load balance more ports next to those. Of course, I've not found docs on this topic on the adobe site.

    Any help would be appreciated.

    Thank you.

    Your JBoss is not yet fully configured for LiveCycle 8.0.1.  There is a period of time what documentation of LiveCycle accidentally excluded the following configuration steps:

    Add the following XML to define the few plants connection to %JBOSS_HOME%\server\all\deploy\jms\hajndi-jms-ds.xml


        true
        adobe_JmsQueueXA
       
        JMS - ra.rar
        org.jboss.resource.adapter.jms.JmsConnectionFactory
        JMS adapter
        javax.jms.Topic
        JmsXARealm
        Java: / DefaultJMSProvider
     


        true
        adobe_JmsTopicXA
       
        JMS - ra.rar
        org.jboss.resource.adapter.jms.JmsConnectionFactory
        JMS adapter
        javax.jms.Topic
        JmsXARealm
        Java: / DefaultJMSProvider
     

  • Verification of the load balancer

    Can someone suggest me, what is the best possible to check if my query selects are running on both nodes?

    The query specifies a number of active sessions on each instance.

    TMP_USER has 3 active sessions on the instance 1 and 1 session active on the instance 2. So yes, the load balancing seems to work.

    You can join gv$ session to gv$ sql by INST_ID select and sql_id to show the transaction.

  • Vary the size of the host and the load balancing

    I have a 4 4-host ESX cluster that is almost the maximum ability to manage virtual machines ~ 80 (and growing).  The hosts are configured with 4 to 8 cores and 32 GB of RAM each.  RAM is currently the bottleneck; Processor is not far behind.  I plan to replace one of the hosts with a much larger machine, 12 cores, 96 GB of RAM.  If a host is significantly larger than the other hosts in a cluster, DRS will still do a good job of load balancing?  I guess the DRS will place multiple virtual machines on the host to the largest.  Is there a risk of DRS. putting too many virtual machines on the largest node?

    Until the cluster is in CVS mode, or processors are compatible vmotion, you can vary the size of the resource of physical machines in the cluster.  DRS will try to balance the load, the better it can over all cluster resources.  Depending on your level of DRS aggressive, improving to a particular machine in terms of past performance is considered, so more that likely, that you will have more vm on the host of the largest.

    -KjB

  • Maxum interfaces for the load balancing wan

    Hi all

    You know the interfaces maximum wan that I can use for load balancing?

    Hi Iimran,

    Lets say your sonicwall has N interfaces. You can use the interfaces wan (N-1) for load balancing

    Kind regards

    Barath R

    #IWork4Dell

  • Limitation of the load balancing VPN3000

    Dear all,

    How many devices can be configured for balancing the load of solutions?

    What is the upper limit?

    Can I assume that if configure US 2 devices, the throughput will be be200 MB, flow of four aircraft is 400 MB, etc.?

    Any thoughts?

    Best regards

    Engel

    No, no, the traffic is not load balanced between all hubs in the group, that the connections are. For example, when you connect with a VPN client address bundle, concentrators determine what hub is lightly loaded, your connection is then completed and supplemented by this hub. All traffic goes between your client and the hub only, like any normal connection. There is no increase in bandwidth to this connection.

    In regard to the number of devices you use, we have tested successfully with 8, but there is no theoretical limit.

  • Can someone tell me what the recommendation of Oracle is on how to best configure the load balancer?

    We are currently using the "configuration.properties" file to identify load balancing our servers, but we are curious to see if it is the recommended method to configure load balancing, or if there is a better way.

    I opened a case with Oracle support and asked the same questions - entry configuration.properties of the file servers is the only supported method used by Peoplesoft to balancing upward through 8.54.

    See also: how the Installer Application Server Load balancing and failover (Doc ID 1252846.1)

  • Difference between the Port ID of the load balancer and MAC?

    There are three strategies for load balancing in 4.0 (one more now in 4.1):

    Function hash IP route

    Route based on the originating Virtual Port ID

    Route in function interference source to the MAC

    I think that I understand perfectly the "IP hash" and how it relates to switches, but what really is the difference between 'source MAC' and 'Port ID'?

    They seems both to do something very similar, which is attached a VM to a physical network card. Why someone should choose the CBC MAC and why the Port-ID? Is there a difference in the way that traffic will extend that could be interesting, when you do a design?

    Hello.

    To simplify, to really all boils down to the formula used to distribute traffic natachasery.

    "Discover Ken Cline" [the great vSwitch debate - part 3 | http://kensvirtualreality.wordpress.com/2009/04/05/The-Great-vswitch-Debate%E2%80%93part-3/] "for many more details on each option works.

    Good luck!

  • Active ADF data service does not work when the load balancer compresses

    Hello

    I have Active Data service table in a page.
    After you enable the setting cache and turned on compression on the hardware load balancer, Active data service table refresh no more in the application.

    We use F5 for balancing load and data compression.

    Pointers?

    Ryan

    You can check if your F5 loadbalancer has enabled text compression.
    Disable compression of text.

  • White space behind the loading Animation

    I have a DW doc, with black color background defined in the properties of the page.

    I have a table with text and a sfw. When the page opens in the browser, like loads of animation there is a big white hole in space of swf. I tried to darken the picture in background and same color makes a black png for the table to bind to. The horrible white hole the rest.

    Been to all the patches?
    example of
    www.cfhda.com

    Select the SWF in DW - change the * background * color in the Panel properties of DW.

    Chris Georgenes
    Animator
    http://www.Mudbubble.com
    http://www.keyframer.com
    Adobe Community Expert

    *\^^/*
    (OO)
    <---->

    iJack555 wrote:
    > I have a DW doc, with black color background defined in the properties of the page.
    >
    > I have a table with text and a sfw. When the page opens in the browser, as the
    > animation loads there is a big white hole in space of swf. I tried to blacken
    > the table in background and same color is a black png for the table to
    > link to. The horrible white hole the rest.
    >
    > Know all the patches?
    > example
    > www.cfhda.com
    >

  • Console Proxy doesn't work is not behind the edge load balancer

    I have a strange problem. I set up a load balancer with vShield Edge. Behind the load balancer, I have two cells vCloud. The Web interface works very well for users, but trying to connect a VMRC to view remote screen it displays 'connection' and then the session is disconnected.

    Then I stop the first cell and users can establish a VMRC connection again. When I activate the first cell once again, the web interface continues to work, but not the proxy of the console. Then I stop the second cell and now elements of the console working again.

    Any tips?

    Gabrié

    Have a similar setup and had the same problem.  Two things to check.  Go to c:\users\\appdata\local\temp\vmware- and open the last file vmware-vmrc - xxxx.log.  Towards the end, it should tell you why it's a failure.  For me, it was a conflict of thumbprint SSL, dating back to the different SSL certificates on the cells.  Also, be sure to vCloud Director Administration-Public address you have the right audiences VCD console address specified. To resolve the inconsistency of my mark, I just created a file certificates.ks a cell and then copied on the other cell and reran the script configures.  Good luck with VMware to help.  I opened a folder for this issue 6 days ago and have yet to get any help!

    -Craig

  • The implementation of hyperion IR application load balancing while 2 servers point to a DB?

    There is a DB production. Some time need to configure the load balancer for Hyperion interactive report achieve high availability.

    As know there are a lot of method to implement load balancing, want to know if

    given two machines virtual (each of them has its own application server), and two of them going to point to the same DB via shared Assembly called/U01 player.

    After the official documentations of oracle documented, there are scarce resources can refer to, any who knew this case of configuration before?

    Hello

    We have implemented this type of solution:

    (1) server 1: install and configure in usual way. Better to use different patterns for each product.

    When you configure Reporting and analysis framework services give repository location as shared drive location.

    (2) server 2: Installation of any product that has been installed in the server 1. While configure the database for the shared services registry point to detail diagram 1 server, it automatically configure the database for all the other remaining products.

    When you configure Reporting and analysis framework services give location of the repository as a shared drive which gave in Server 1.

    Make sure that the Shared disk is accessible from both servers.

    You can deploy applications weblogic Server from Server 2 by giving details of server 1. ensure that the weblogic Server 1 service must always be upward and running for Server 2 workspace to work.

    So if we set up the web server in both servers, then you must have load balancer and configure logical web address to this server for load balancing.

    If you configure only in one of the server, then this workspace server that url will act as load swing url.the problem with this is always THAT OSH must be running or workspace url will not work

    hope you understood.

  • Two shared the Application layer without load balancer

    Hi all

    I created the system of Application of layer two without the load balancer.

    EBS: 12.1.3 DB: 11.2

    I have two URLS:

    https://XYZ:8002/OA_HTML/APPSLocalLogin.jsp

    https://ABC:8002/OA_HTML/APPSLocalLogin.jsp

    I run the auctoconfig on the last node abc. When I try to access the https://xyz:8002/OA_HTML/APPSLocalLogin.jsp, it automatically redirects to https://abc:8002/OA_HTML/APPSLocalLogin.jsp

    If autoconfig on xyz last execution, https://abc:8002/OA_HTML/APPSLocalLogin.jsp URL automatically redirects to https://xyz:8002/OA_HTML/APPSLocalLogin.jsp.

    I know in 11i is the behavior, but according to my understanding in R12 this shouldn't ' e be the case because another application works very well.

    Concerning
    Sourabh Gupta

    Please see (multiple Application nodes configured without Load Balancer Cause Login Redirection [1362885.1 ID]).

    Thank you
    Hussein

  • The console to load balancing proxy

    Hi people,

    I have set up 2 servers of vCloud Director for redundancy:

    Server 1:

    http address: vcd1.example.com

    Console proxy address: vcdcon1.example.com

    Server 2:

    http address: vcd2.example.com

    Console proxy address vcdcon2.example.com

    I've set up a public URL through a load balancer: vcd.example.com. It works perfectly - I can connect to the public URL on the load balancers and functions of vCD correctly.

    It is:

    https://vcd.example.com load balanced back end vCD servers vcd1.example.com and vcd2.example.com.

    Now I try to get the proxy to the console through the load balancers and have not been able to get this working.

    First, I checked the remote console works when connecting to the address consoleproxy on the servers of vCD, for example vcdcon1.example.com and vcdcon2.example.com. The console connects very well and I can connect to the virtual machine.

    I set up one address public consoleproxy on the load balancers, for example https://vcdcon.example.com that load balances at vcdcon1.example.com and vcdcon2.example.com.

    When the remote to a computer virtual console is launched, I get the following error:

    Unable to connect to the MKS: Timeout during an attempt to read.

    I tried this on a Juniper DX load balancer and a device of Zeus Traffic Manager and get the same results. On Zeus, I can see the last HTTP request sent from my PC before the above error is visible:

    CONNECT 10.10.10.100:902 HTTP/1.1

    10.10.10.100 is the public proxy IP console, i.e. vcdcon.example.com.

    I use self-signed certificates free for the public and back end https.

    Someone at - it work for vCD consoleproxy addresses of load balancing?

    TIA - Trevor

    Hi Trevor,

    try changing the load balancing policy, try using a simple tcp strategy, without cookies management

    Max

  • Load balancer and the consolidation of NETWORK cards

    Hello

    We recently had to our file VMware Server after a bit nasty failure of his original material.  Since we moved, it mostly worked OK, but we don't get the occational network shares paw when large files are thrown on.

    ESXi host, sure it works use 5Gbit ethernet adapters on the same Virtual Switch.  Looking at the traffic it would seem that all traffic flows in just a single NETWORK adapter and it is not much at all through the others.  Is something that I need to set it up so that it can better load balance between network cards?  Or is it a document anywhere who recommended settings for multiple network cards?

    I found a vDS topic but we have not undertaken more liciencing on most of our servers.

    We run VSphere 4.1 via the Vcentre server.

    Thanks for the help.

    faster4233 wrote:

    What you say makes a little more sense on what I see.  There is very little traffic flowing through other NETWORK cards, but is perhaps because there isn't any real traffic goes to them.  I thought that VMware may use multiple NICs, if it was required that is why I thought I'd see more data on the other.

    Curiosity is anyway that I can combine NICs for more flow using VMware?

    The load balancing, you can achieve with VMware is not a "real" load balancing, this is more a static distribution of traffic in accordance with the policy, you have chosen.

    You use means that according to the virtual switch port ID the vNIC to the host is connected to a specific bear is chosen. This unique vNIC traffic will use this bear as long as this bear does not fail. In this case the guests more with vNIC, you have the better are used Teddy.

    Other policies can be better for other scenarios. For example, 'Hash IP' uses the source IP address and target to choose a teddy bear. It is a good policy for a server with a vNIC single file and many different communication partners. The 'Source Port' policy route all traffic through a teddy bear so that 'Hash IP' policy would use many Teddy as not what ID port is used, but the communications partners. And a file server must have many of them, more than it has of vNIC.

    AWo

    VCP 3 & 4

    \[:o]===\[o:]

    = You want to have this ad as a ringtone on your mobile phone? =

    = Send 'Assignment' to 911 for only $999999,99! =

Maybe you are looking for

  • How can I get rid of your invasive UN firefox like declaring your independence tab?

    Since I upgrade, two tabs open, a declarant declare your independence. I think it's very Microsoftish for this force on people and I can't put my tab back to what I want. I like firefox but it's completely unacceptable. Remove or I'll go to chrome

  • water damaged iphone memory are accessible by others?

    So I found a place that is ready to buy my water damaged iphone 5s, problem is that they want remove me device from my icloud account and I'm not sure and didn't quite stupidly asking why they need me to do, so I am wondering here if they are able to

  • Installing WXP on Satellite L300 (PSLB8E)

    Hello I have a Satellite L300 (PSLB8E) laptop computer and I want to install Windows XP, but unfortunately, I still get an error message after you start the XP CD (XP Setup has encountered a problem, the Setup will leave...) Is there a solution?

  • Stuck in a larger size?

    My son was playing a game on the computer and now the whole page is stuck in a large format. I tried the zoom it works only on the lower part of the page, the rest is still great... I can not understand how to operate this new... Can you help me?

  • Appvolumes attached (Nitro pro) (Adobe Acrobat) (DWG True View) stop word Macros to run.

    HelloWe get this error for some users of Microsoft Word 2016: "the Macro cannot be found or has been disabled because of your macro security settings.IF I step forward and detach the appvolumes. -I can then go to Word and run the Macro from the Ribbo