@david.cw.liu1 wrote:
HI,
What are the pros and cons of using ClearPass (Wireless, Wired NAC, TACACS+) Virtual IP or Physical IP address?
How to decide which one is better for belwo scenario?
Thanks.
Situation
- 2 data centres
- 2 x CPPM at each data centre
- 10 x branch WLAN controllers
- 200 x switches which need TACACS+
I would say that the VIP address is designed for guest page redirect on CPPM, where you can only redirect users to a single URL but you require some sort of redundancy. With TACACS and radius, you can always add a second ip address in the NAS device for redundancy, but with guest scenarios, that is not possible. The VIP is for that scenario for people who cannot or do not want to put their guest traffic in front of a load balancer for redundancy.