<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ise radius/nac in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006657#M202147</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thanks for your reply.&lt;/P&gt;&lt;P&gt;Here is my in depth problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3666442#3666442"&gt;https://supportforums.cisco.com/message/3666442#3666442&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Jun 2012 03:06:17 GMT</pubDate>
    <dc:creator>edondurguti</dc:creator>
    <dc:date>2012-06-25T03:06:17Z</dc:date>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006655#M202145</link>
      <description>&lt;P&gt;Can ISE 1.1 act as a RADIUS for WGB through WLC?&lt;/P&gt;&lt;P&gt;thank&amp;nbsp; you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006655#M202145</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2019-03-11T02:12:46Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006656#M202146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it can, ISE supports the protocols found in this QA regarding WGB - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/wireless/ps441/products_qanda_item09186a0080094644.shtml#q11"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps441/products_qanda_item09186a0080094644.shtml#q11&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the authentication protocol configuration section in ISE - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_auth_pol.html#wp1146161"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_auth_pol.html#wp1146161&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 04:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006656#M202146</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-24T04:48:28Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006657#M202147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thanks for your reply.&lt;/P&gt;&lt;P&gt;Here is my in depth problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3666442#3666442"&gt;https://supportforums.cisco.com/message/3666442#3666442&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 03:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006657#M202147</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-06-25T03:06:17Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006658#M202148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using eap-fast or mac filtering to get the workgroup bridge authenticated to the same ssid? I had a chance to skim through the thread an it seems that you are being redirected to the web portal for authentication, is that correct? If you are using mac filtering then we may have to manually add all the WGB to a specific endpoint group and build a policy so that all WGB on receive an access-accept with no additional attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is not the case please summarize where you are at this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 03:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006658#M202148</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-25T03:57:36Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006659#M202149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarik,&lt;/P&gt;&lt;P&gt;Thanks for your answer, here is the problem !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to do PROFILING/POSTURING and all that for wireless clients here is what's needed:&lt;/P&gt;&lt;P&gt;Need to go to WLC (wireless controller) and choose RADIUS/NAC for the SSID.&lt;/P&gt;&lt;P&gt;So SSID = test RADIUS/NAC - then all normal clients go through ISE and get postured and profiled and all that works fine except...&lt;/P&gt;&lt;P&gt;WGBs cannot connect to SSID=test at all and they do not appear on ISE as an attempt at all.&lt;/P&gt;&lt;P&gt;As soon as I remove option RADIUS/NAC from WLC wgb connects and shows up on ISE fine and get authenticated ---&amp;gt; you would say well there you go that's ur problem &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt;, well yeah but if i DISABLE Radius/Nac option from WLC I lose the ability to control normal users that connect to SSID=test so it would just be PERMIT/DENY ACCESS based on username and the whole point of ISE would be ACS or Simple Radius Server.&lt;/P&gt;&lt;P&gt;Do you get my point?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.s so for me to POSTURE/PROFILE wireless clients I need to use RADIUS/NAC option and for WGBs I have to setup a NEW SSID and leave that SSID without RADIUS/NAC option so it can only authenticate through ISE and not posture/profile clients, and I do not need to posture/profile clients behind WGB (it would be great but I don't necessarily need to, and I know they don't support CoA Change of Access attribute in RADIUS)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 04:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006659#M202149</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-06-25T04:06:07Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006660#M202150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an article that states WGB is not supported, however I think the scope of the document focuses primarily on posturing so I dont want to give up hope yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-18121"&gt;https://supportforums.cisco.com/docs/DOC-18121#Limitations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you associating your WGB to the production SSID? Are you using mac filtering or eap-fast (excuse my ignorance since this a AAA forum I am not well versed in the WGB arena).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think if you can create a test condition where the WGB is statically assigned to a endpoint group, enable mac filtering on the ssid, and select an authoriziation policy where the endpoint group of the WGB matches an access accept only authorization profile (no redirect, no acls, just send the access accept) then this may get the ball rolling and drop the webauth messages you are seeing the in the debugs. Let me know if that works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 06:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006660#M202150</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-25T06:35:45Z</dc:date>
    </item>
    <item>
      <title>ise radius/nac</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006661#M202151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you sir will try to do that, but as of right now I had WLC demo&amp;nbsp; and I don't have it now, but will soon get the real thing of all ISE&amp;nbsp; WLC AND NCS and will do some further testing.&lt;/P&gt;&lt;P&gt;I have like 800 wgbs and if I have to create another ssid and re-configure them all thta would be&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 16:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-nac/m-p/2006661#M202151</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-06-25T16:19:07Z</dc:date>
    </item>
  </channel>
</rss>

