Cisco Identity Services Engine Installation Guide, Release 3.5

PDF

Cisco ISE infrastructure requirements

Want to summarize with AI?

Log in

Overview

Provides a definite set of infrastructure requirements and limitations for deploying Cisco ISE.

Reliable connectivity between Cisco ISE and your underlying network infrastructure is important for secure operations. These infrastructure ports facilitate essential communication protocols such as RADIUS, TACACS+, and SNMP between Cisco ISE and your network devices.

This section describes the infrastructure requirements and design considerations for deploying Cisco ISE. It outlines management access restrictions, network interface limitations, port and firewall requirements, and supported deployment models to help ensure proper connectivity, policy enforcement, and Cisco ISE operation.

Management interface requirements

Management access to Cisco ISE is restricted to the management interface.

  • Management access is allowed only through Gigabit Ethernet 0.

  • Administrative access includes the web-based GUI, CLI, and APIs.

  • Other network interfaces are not used for management access.

Network interface and VLAN requirements

  • Cisco ISE interfaces do not support VLAN tagging.

  • Switch ports connected to Cisco ISE nodes must be configured as access ports.

  • VLAN trunking must be disabled.

  • Each network interface card (NIC) can be assigned a unique IP address.

Ports and firewall requirements

Cisco ISE uses a restricted port model and opens only the ports required by enabled services.

  • Ports not explicitly required by active services are denied by default.

  • The ephemeral port range used by Cisco ISE is 10000–65500.

  • Firewalls must allow required service ports and the ephemeral port range.

RADIUS traffic handling

  • RADIUS authentication and accounting traffic is accepted on all available NICs.

  • RADIUS traffic is not limited to the management interface.

Cloud and virtual deployment requirements

  • VMware on Cloud deployments are supported.

  • Connectivity must be provided using a site-to-site VPN.

  • Network address translation (NAT) and port filtering are not supported between Cisco ISE nodes and network access devices.