<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE : MAB, SoA ... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214921#M136676</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to implement Cisco ISE on my network so that 802.1x authentication will be operationnal.&lt;/P&gt;&lt;P&gt;When I give a look to this document : &lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0.4/compatibility/ise104_sdt.html#wp55038" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0.4/compatibility/ise104_sdt.html#wp55038&lt;/A&gt;&lt;BR /&gt;There's a lot of Catalyst 2950 on my network and I see that some features aren't supported on these devices : MAB, dACL, SGA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the consequences of these non-supported technologies ? I've found out for instance that MAB was used to authenticate devices which doesnt allow or support 802.1x, so will the printers of my network still work ?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And what about dACL and SGA ? Are these features really useful or isn't it that bad if I can't use them ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:25:28 GMT</pubDate>
    <dc:creator>yoshipower</dc:creator>
    <dc:date>2019-03-11T03:25:28Z</dc:date>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214921#M136676</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to implement Cisco ISE on my network so that 802.1x authentication will be operationnal.&lt;/P&gt;&lt;P&gt;When I give a look to this document : &lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0.4/compatibility/ise104_sdt.html#wp55038" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0.4/compatibility/ise104_sdt.html#wp55038&lt;/A&gt;&lt;BR /&gt;There's a lot of Catalyst 2950 on my network and I see that some features aren't supported on these devices : MAB, dACL, SGA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the consequences of these non-supported technologies ? I've found out for instance that MAB was used to authenticate devices which doesnt allow or support 802.1x, so will the printers of my network still work ?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And what about dACL and SGA ? Are these features really useful or isn't it that bad if I can't use them ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214921#M136676</guid>
      <dc:creator>yoshipower</dc:creator>
      <dc:date>2019-03-11T03:25:28Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214922#M136677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yoshipower,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Catalyst 2950 does not support MAB, SGA, CWA, LWA, dACL, except that it&amp;nbsp; supports 802.1x only. So this means that you can only use dot1x&amp;nbsp; authentication but profiling, client provisioning, posture assessment,&amp;nbsp; change of authorization features are not available to you on Catalyst&amp;nbsp; 2950. You have already gone through the ISE Network Component&amp;nbsp; Compatibility document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; So if you feel only user authentication fulfills your requirement you&amp;nbsp; can set up dot1x authentication but it should not be enabled on the&amp;nbsp; ports where devices like printers, IP phones, camera UPS etc are&amp;nbsp; connected. Briefly we can say that only user authentication is available&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ashok&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 09:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214922#M136677</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-13T09:46:44Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214923#M136678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ashok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your proper answer, you're really fast in this forum. &lt;SPAN style="font-size: 10pt;"&gt;My network is composed of nearly 60% of 2950 switches but there's a lot of other devices such as 2960 and 3750 switches. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;However, I don't have a lot of devices which don't support 802.1x auth (only a dozen of printers) so I guess I could turn off dot1x on them as you advised me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the unavailable features on 2950 useful ? &lt;SPAN style="font-size: 10pt;"&gt;I mean by that that if they are really essential, I would have to invest in new switches and it's a considerable question in terms of money... I haven't deployed ISE yet so I'd like to be sure of my theorical study before going on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks a lot !&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 10:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214923#M136678</guid>
      <dc:creator>yoshipower</dc:creator>
      <dc:date>2013-05-13T10:08:07Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214924#M136679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with ashok...devices such as printers and cameras don't support dot1x and they completely rely on MAB. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you turn on dot1x and mab on the switches and set the order/priority. It will work for both the devices, one that support dot1x and other that support MAB so it will work on a failover method. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd say 3750 and 3560 POE are the best switches to implement flex auth that includes dot1x, MAB and web-auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SGA is an advanced feature and not every deployment includes this feature.&lt;/P&gt;&lt;P&gt;SGA Features and Terminology &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_sga_pol.html#wp1058113"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_sga_pol.html#wp1058113&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 10:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214924#M136679</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-13T10:17:26Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214925#M136680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to manage your limited investment you can follow a phased&amp;nbsp; implementation approach. Though it would be little laborious. You can&amp;nbsp; swap 2950 switches with 2960 or 3750 wherever you have devices like&amp;nbsp; printers. So you can connect your printers on either 2960 or 3750&amp;nbsp; switches only and PCs on 2950 switches. Then setup flexauth (MAB &amp;gt;&amp;nbsp; dot1x) order and priority as required, on those switches where printers&amp;nbsp; etc are connected. Jatin Katyal has righly suggested, I agree with him&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; With this approach, you can setup and enable all other features i.e.&amp;nbsp; profiling, client provisioning, CoA for certain identity groups which&amp;nbsp; are connected on supported switches (2960, 3750)&lt;/P&gt;&lt;P&gt; Note: Please make sure to review the IOS on your 2960 switches and&amp;nbsp; compare the same in “ISE Network Component Compatibility Document”&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 11:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214925#M136680</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-13T11:23:12Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214926#M136681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi back, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a small update about my topic. &lt;SPAN style="font-size: 10pt;"&gt;I've talked a bit with my boss and it turns that he wants ISE to be deployed to ensure full security, which means I need to use profiling and provisioning for users to authenticate with NAC agent !&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thus, I'd like to know which features are required for my solution. What do I need : CoA,&amp;nbsp; Web Auth ? I'm a bit lost...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; I'm guessing I'll have to change my old 2950, but what about my 2960, 3950, 4510 and 4507 switches ? Do they support what I want to do ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you for your help ! &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 07:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214926#M136681</guid>
      <dc:creator>yoshipower</dc:creator>
      <dc:date>2013-05-15T07:24:26Z</dc:date>
    </item>
    <item>
      <title>ISE : MAB, SoA ...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214927#M136682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I guess everything looks fine except 2960 doesn't support DACL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 09:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-soa/m-p/2214927#M136682</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-15T09:19:07Z</dc:date>
    </item>
  </channel>
</rss>

