ISE iPEP + 3rd party device VPN bridge or route mode

Dear All,
I would like to get some advice from the community regarding my idea.
We would like to integrate ISE iPEP with a 3rd party VPN device using bridge mode.
However i can only find documents describing the following scenarios,
- routed mode with VPN device
- bridge mode with Wireless Controller
So the questions is that is bridge mode supported if i would like to integrate ISE iPEP with a 3rd party VPN device or is it even possible to achive this kind of deployment?
Thank you in advance.
Best Regards,
Erik Molnar

Thanks for the reply Marcin.  Both of your suggestions are good ones, however in this scenario both DC firewalls are alive at the same time, so there needs to be some kind of logic on the device at the remote site to say that it should only use tunnel B if tunnel A is down.
Thinking on this, is it possible to run an 'interface' or 'routed' mode IPSEC VPN with the ASA?  I know this is possible with the Fortigates and think it's the default mode for Junipers.  If that were possible we might be able to have both tunnels up and have OSPF run over them which would be another way to solve this problem.

Similar Messages

  • 3rd party device support

    Hi,
    Is there going to be any change in the way MARS would support 3rd party devices (non-cisco) like checkpoint, Intrushield etc in future?
    Thanks in advance,
    Valsa Raj

    1. Discovery supports many non-CDP modules such as ping sweeps, ARP cache lookups, and routing table lookups.  However, Topology Services still requires CDP to build interconnections between devices.
    2. Yes, non-Cisco devices will show up on the Topology Map with a generic icon.
    3. There is no restriction except it has a maximum of 50 devices.
    4. The Fault component of LMS 4.0 can integrate with HPOV NNM.

  • Use of files dowloaded from i-tunes store on Roku (3rd party device)

    Hello,
    I have a Roku soundbridge system which play my music from my Mac compute r(via wifi). Unfortunaley it does not succeed to play the files bought on i-tunes store as it says they are protected. How can i take out the protection or have it read by my system. On roku site, i only find "apple does not allow streaming of files downloaded from their music store to 3rd party device." Is there any solution for me to listen to the albums i have bought on my system??? thks for your help

    Sorry, but as Roku's web site says, no third-party devices can play tracks purchased from the iTunes Store. Tracks from the iTunes Store can only be played in iTunes or QuickTime Player or on an iPod, Apple TV, iPhone or iTunes-equipped Motorola cell phone.

  • PI2.1 3rd Party devices

    Hi,
    I have recently installed a HA pair of PI2.1 NCS appliances and so far so good.
    I have a number of 3rd party device that I would like to add.
    I have uploaded the specific MIB's for these devices and created Custom SNMP templates to use to monitor them. These templates have been deployed via "Monitoring Deployment" on the 3rd party devices.
    The question I have is where can I now see the detail that PI is retrieving when it SNMP polls these 3rd party devices using the custom template.
    I would have thought it would be visible in the Device Work Centre when you click on a device, like it is with the Cisco ones but nothing else is showing except for the usual IP address, product family etc  information.
    Any ideas ?
    cheers
    Rich

    Changing the local ssh client to v2,1 doesnt work.
    You need to change /etc/ssh/ssh_config
    # Protocol 2,1
    >>> comment out
    not the sshd_config, this will change the SSH-access to the PI-server self.
    In our case we extended the vty input to telnet for the few older ssh1 only image devices
    Steffen

  • HT204368 Can you (Handoff) control your iphone with 3rd party devices ? (Like making calls, sending message, etc...)

    I am wondering if you can control your iphone or other iOS devices with 3rd party devices? I have in mind like making calls, sending sms, etc....
    Thank you!

    No,

  • CSM bridge vs router mode

    Hi,
    Can the CSM be used in both the bridge and router mode for different VLANS ? Or does it need to use all router mode and all bridged mode ?

    you can have a mix of both.
    Gilles.

  • CSM concurrent bridge and router mode

    Hi,
    Is it possible on the CSM to use bridge and router mode at the same time ? Or is it only router mode or only bridge mode ?
    E.g. in the example below, when using HTTPS entering the vlan 3 , it will be bridged to vlan 3....But when using HTTP entering vlan 3...it will be routed to vlan 4... Will that work ?
    Thanks
    vlan 3 client
    ip address 3.3.3.1 255.255.255.0
    vlan 3 server
    ip address 3.3.3.1 255.255.255.0
    vlan 4 server
    ip address 4.4.4.1 255.255.255.0
    vserver HTTPS
    vlan 3
    virtual 3.3.3.10 tcp https
    serverfarm HTTPS
    serverfarm HTTPS
    no nat server
    no nat client
    real 3.3.3.11
    inservice
    real 3.3.3.12
    inservice
    vserver HTTP
    vlan 3
    virtual 3.3.3.11 tcp http
    serverfarm HTTP
    serverfarm HTTP
    nat server
    no nat client
    real 4.4.4.10
    inservice
    real 4.4.4.11
    inservice

    HI Michel,
    first of all you can run bridged and routed mode at the same time but you can not define the same vlan as client and server. If you would change the above config from vlan 3 server to vlan 30 server and place the reals in vlan 30 it will work. A proper layer 2 configuration is for sure the prerequisit.
    Kind regards,
    Joerg

  • Any 3rd party utilities that fix full screen mode for multi-monitor users?

    I am a multi-monitor user.  As multi-monitor users know, full screen mode is basically useless since if you try to go full screen on one monitor, it causes the other monitor to go blank and become unusable (at least with most programs).  Are there any 3rd party utitilities or fixes for this?
    Thanks

    Spaces, which is what this functionality stems from, was limited in that it used your entire setup and switched all of the screens over; space to space. I never used spaces because I always had multiple monitors and I was always working with multiple apps simultaneously that I wanted to be able to reference while working on the others.
    Now they call Spaces, "mission control" and changed the appearance of it, but the functionality remained the same, each workstation comprised all of your monitors, and would switch over all of them when switching to a new "Desktop".
    Fullscreen apps wrongly assumes that it can take the functionality of the afformentioned MS/Spaces and use it for one app, negating the whole idea of why someone would have multiple screens (real estate to work with other applications).
    If they stop considering multiple monitors as one Workspace, they can then make it so they are asynchronous "tablets" instead of one conjoined entity.
    So, you say people have been asking about this for 2 years, I've been asking for this for 5!
    The issue here is, the only answer is to not use it. Making Mission Control and Fullscreen apps completely ignored by people like us, where I could be using both functions to glide around my work station and three monitors, mixing and matching which apps I want to be viewed on each separate monitor, to perform one single task; together.
    It would actually reward people who wanted to utilize Thunderbolt technology and have more then one monitor.
    There is no telling why apple chose to push out something that would only support the casual user, with one display, but the only direct way to let apple know that we feel limited by the OS is to send feedback. Even though it seems that we are powerless in this situation, I hope that they do consider how to make this function better.
    </rant>

  • Bridge or Router Mode?

    I have adsl modem asus dsl13 (mode adsl2+ ). Provider has a PPoE.
    What a proper option for TC - bridge or router?

    You can do either bridge on the modem and router on the TC.. or router on the asus modem and bridge on the TC.
    There is hardly any difference in overall performance.. since adsl is the limiting factor here.
    But a few things to consider.
    Pro router in the TC
    1. The TC is a much faster router than the asus, if you need speed. (For normal setup makes no difference)
    2. The TC often behaves better when it is the router to clients running time machine. (TC should be main router in the network if you keep having issues and losing connection with it).
    Pro router in the Asus.
    1. The TC is peculiarly apple, and misses out some things important. eg QoS, very important if you are running voip phones, upnp, very important if you run gaming consoles.
    2. If you run the Asus as the main router you have direct access to the modem stats. This is difficult behind a bridged modem.
    3. You can run PPPoA, which is slightly more efficient encapsulation method if your ISP supports it. For many people the ISP does not support pppoe so they have little choice. Sometimes PPPoA is the preferred method by the ISP and is just more reliable.
    For the vast majority of people there is no right answer. Pick what works for you.

  • Ethercat 3rd Party Device Profile XML File not complete

    Hi all,
    I'm trying to use a Schneider LXM32 servo drive coupled to a NI cRIO 9074 Ethercat master.
    The problem is that my LabVIEW project is not showing me the full device profile.
    There are 4 available PDO for this device :
    1) Cyclic Synchronous Position
    2) Cyclic Synchronous Velocity
    3) Cyclic Synchronous Torque
    4) Free switching beetween 1) 2) or 3)
    BUT, I only see the firts PDO parameters after importing the xml file. If I open the xml file manually, I see that all the PDO are available.
    The xml file is available in this post.
    Of course, I need to operate in the 4) mode, not the 1)
    Help me, please....
    Sébastien MICHAUD
    CLD
    Attachments:
    Schneider_Electric_LXM32M_V114.zip ‏18 KB

    Hi,
    Thank you for your answer.
    I successfully modified the XML file of my Schneider drive :
    Now I have a lot of others problems (I have made a request on NI France, I supposed you are the one who phoned me today).
    1) The XML file of my LTi DRiVE (another drive of the test bench) is done like this (see attachment):
    1) I can't move the Sm tag because it's already everywhere
    2) I don't understand why 4 devices are exposed.
    Additionnaly, see below the LabVIEW project with this device :
    3) The I/O exposed for the 2 Devices (Schneider and Lti) are shared variables. But I want to poll these I/Os every 125µs. The scan engine can run at 1 ms. So, if a put a "percentage of each scan period" to 1% (the default value is 40%), will I be able to poll every 10 µs ?
    In this example :
    https://decibel.ni.com/content/docs/DOC-11191
    The scan period is 4 ms at the best, so with 40% of each scan period, it represents 1.6 ms.... am I correct ?
    4) Is it necessay to use NI SoftMotion (https://decibel.ni.com/content/docs/DOC-11191) to get/set data to a motor drive ? Is it much more easy with NI SoftMotion ?
    Thanks,
    Sébastien MICHAUD
    Attachments:
    LUST_22_SO.zip ‏2 KB

  • Line in for itunes - Use computer audio in or 3rd party device

    I wanted to know if there were any devices or a way to get something recognized by itunes that you could plug in something like a live band, that would be recognized as a device and then just select that device and it would play the audio from that thru itunes.
    The reason for this is I use apple remote and airport expresses throughout my house to play music. It would be nice to be able to pipe in sound from another source and select it thru apple remote and play that audio thru the airportexpresses.
    For example, someone brings over a record player and we hook it up, plug the RCA outputs into the device or line in on the computer. Then when itunes is opened the device/line in shows up as a source, and I guess to fit into apples schema, there would be one "song" on the device and it would just "play" that which would then send the incoming sound thru itunes and play over the speakers thru airportexpress.
    Im suprised there is no device or option to play "line-in" or maybe there is a way to have the sound line in of the computer be used. Im sure there are lots of applications for this.  I suppose its possible apple doenst want this option but maybe someone out there has some kind of work around to accomplish my goal.
    Thanks
    james
    Maybe it could be something line a live podcast or personal radio station that could be set up. I just thought of this looking at the catagories.

    I eventully figured out how to do this. It cant be done in Itunes. You have to use airfoil not itunes to broadcast to the airtunes speakers. You can select any input or program to supply the sound.  If you want to control this from your iphone you need to install ReeMote and the ReeMote server on your mac to control airfoil Volume, you can not control the input selection from the reemote application.  This must be done on the Mac but it defaults to the previous selected input all the time on startup.

  • Connecting 3rd party devices to my computer

    How do I connect lap tops and i phones to my imac so that they can access app stores etc?

    Like I said before, you can connect 2 iPods to one computer. However, there are multiple options. If you don't care whether some of his songs are on your iPod, and vice versa, you can use the same user on the computer. Now... If you each want your own library, there's two ways you can set this up: #1 - Create a new user on the computer, and install iTunes 7 there. Then, one of you use one user, and the other can use the created one. The songs can be different on in iTunes on either user, it'w a whole new library. #2 - If you don't want to create a new user on the computer, you can set your iPods to "manually update songs" so that iTunes doesn't automatically put all the songs in the library on the iPod. With this method, you have to manually drag songs you want from iTunes to your iPod icon in iTunes. That way, you can selectively put your songs on your ipod and he can put his on his iPod using the same library.
    Hope this helps

  • Bluetooth Audio Control from 3rd party devices

    I just bought 2010 Mazda3, and it has Bluetooth handsfree calling and audio capability. I have paired my iPhone 3G to my car and can stream music from my iPhone to my car stereo via Bluetooth but I cannot control my iPhone through the car's controls. My Mazda has the ability, but Apple needs to update to the newer/advanced Bluetooth profile.
    Attention Apple: Please update to A2DP AVRCP

    BobbyR1984 wrote:
    ...Attention Apple: Please update to A2DP AVRCP
    Welcome to the discussions,
    This is a user to user forum and Apple will not hear you. You can address Apple directly here: http://www.apple.com/feedback/iphone.html

  • ACS autherization for 3rd party device

    Hi all,
    I am trying to set up AAA authentication and autherization for nortel passport through ACS 4.2 server.
    i am sucessful in getting authentication through RADIUS but need to control autherization of nortel passport through ACS.. Can anyone suggest how to do it. I have mentioned few command of nortel...
    Hardware - Nortel passport 7480 / Nortel Multiservice Switch
    7480
    Software - PCR 9.1
    Commands -
    1) d -p vr/* pp/* ipp log/*
    2) ping -ip(10.2.1.14) vr/2 ip icmp
    3) d -p sig/*
    4) d sig/*
    5) d -p vsr/*
    6) d -p vroute/*
    Need help...
    Regards
    Amar

    Hi all,
    I am trying to set up AAA authentication and autherization for nortel passport through ACS 4.2 server.
    i
    am sucessful in getting authentication through RADIUS but need to
    control autherization of nortel passport through ACS.. Can anyone
    suggest how to do it. I have mentioned few command of nortel...
    Hardware - Nortel passport 7480 / Nortel Multiservice Switch
    7480
    Software - PCR 9.1
    Commands -
    1) d -p vr/* pp/* ipp log/*
    2) ping -ip(10.2.1.14) vr/2 ip icmp
    3) d -p sig/*
    4) d sig/*
    5) d -p vsr/*
    6) d -p vroute/*
    Need help...
    Regards
    Amar
    Hi Amar,
    Check out the below link for radious authorization confguration on ACS
    http://www.ciscosystems.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/c.html#wpxref31687
    Hope to Help !!
    Ganesh.H

  • 3rd party IPS fail open device

    HI all,
    I am looking out for a 3rd party hardware device for IPS 4240 hardware fail open in case if my IPS unit has any hardware problems.
    Please suggest me on different model no/make for any 3rd party devices.
    Thanks
    pratik

    Hi Pratik,
    I am not aware of any.
    However,  Cisco IPS 4260 and IPS 4270-20 support the 4-port GigabitEthernet card (part number IPS-4GE-BP-INT=) with hardware bypass.
    This 4GE bypass interface card supports hardware bypass.
    http://tools.cisco.com/squish/878Dd
    Regards,
    Sid Chandrachud
    Cisco TAC - Security Team

Maybe you are looking for

  • 4.0 SUCKS! HOW DO I GET 3.8 BACK? No Yahoo toolbar or IE Favorites.

    I upgraded to the Firefox 4.0 and now I find that it is not compatible with most of the add-on's and my Yahoo toolbar that I had before. In particular, I cannot access IE Favorites nor can i install the Yahoo tool bar. his application is confusing an

  • Copy/Paste difference in newer versions

    Hello, I developed some problems with my Acrobat Standard 7.0 install when trying to update to 7.1 (it wasn't recognizing my CS2 install disk as the correct source disk it was requesting) so in the mean time I downloaded the latest version so I could

  • Mountain Lion installation, volume damaged

    i'm trying to install ML on my MB but the installer tells me that my volume HDD is damaged and needs repair. In disk utitlity the repair function is not available and i can not stop the mac from booting with the new ML setup assistant. any chance of

  • Restoring the data from table after deletion

    Hi, If  I delete the data from the database (using delete command) , is there anyway to restore that data. I know it looks bit weird but I'm checking whether there is any technique in abap by which we can restore the data. Your help would be apprecia

  • User default format in printing inventory list

    Hi experts, I have a question about the user default print format. When I try to print out a output for inventory list, the print format turn to be a format that I donu2019t want to use, I have to change the format manually everytime. Is there any me