cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1303
Views
3
Helpful
1
Replies

ISE VRF overlapping IP address awareness

jinapark
Cisco Employee
Cisco Employee

Hello everyone,

I'm struggling to find out if ISE have ability to cater for overlapping IP address ranges via VRF.

I noticed that ISE can be used to assign different VRFs via RADIUS, but not clear how it works, I mean how ISE can be aware of overlapping IP address ranges from VRF. Do we must use Trustsec SGT?

Cisco TrustSec Configuration Guide, Cisco IOS Release 15SY - Cisco TrustSec VRF-Aware SGT [Support] - Cisco

Thanks in advance for your help

Regards,

Jina

1 Accepted Solution

Accepted Solutions

hariholla
Cisco Employee
Cisco Employee

Hi Park,

I don't think I understand your question correctly.

If you are talking about Endpoints:

I noticed that ISE can be used to assign different VRFs via RADIUS

               ISE can assign endpoints to different VLANs which can further be part of specific VRFs in the network.   

If the question is about Network devices:

how ISE can be aware of overlapping IP address ranges from VRF

If you are talking about network devices, like a switch or Wireless controller that talks to ISE, then they need to be identified with unique IP addresses. If one or more 'Network Devices' are to be configured with the same IP address, then its not allowed. You get the following error:

Screen Shot 2017-07-20 at 3.00.55 PM.png

Hope this helps.

Cheers!

-Hari

View solution in original post

1 Reply 1

hariholla
Cisco Employee
Cisco Employee

Hi Park,

I don't think I understand your question correctly.

If you are talking about Endpoints:

I noticed that ISE can be used to assign different VRFs via RADIUS

               ISE can assign endpoints to different VLANs which can further be part of specific VRFs in the network.   

If the question is about Network devices:

how ISE can be aware of overlapping IP address ranges from VRF

If you are talking about network devices, like a switch or Wireless controller that talks to ISE, then they need to be identified with unique IP addresses. If one or more 'Network Devices' are to be configured with the same IP address, then its not allowed. You get the following error:

Screen Shot 2017-07-20 at 3.00.55 PM.png

Hope this helps.

Cheers!

-Hari