<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restrict Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846890#M24816</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can we Restrict a client to authenticate on just one physical port?&lt;/P&gt;&lt;P&gt;that's mean the client cannot change its own physical port on a switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2019 05:10:43 GMT</pubDate>
    <dc:creator>mortezasadeghi</dc:creator>
    <dc:date>2019-04-29T05:10:43Z</dc:date>
    <item>
      <title>Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846890#M24816</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can we Restrict a client to authenticate on just one physical port?&lt;/P&gt;&lt;P&gt;that's mean the client cannot change its own physical port on a switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 05:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846890#M24816</guid>
      <dc:creator>mortezasadeghi</dc:creator>
      <dc:date>2019-04-29T05:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846904#M24819</link>
      <description>&lt;P&gt;you would need to set up dot1x authentication, port based&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 05:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846904#M24819</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2019-04-29T05:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846924#M24823</link>
      <description>&lt;P&gt;We need to know your environement, Do you have ISE or any Authentication in your environment. then&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322101"&gt;@Dennis Mink&lt;/a&gt;&amp;nbsp; suggested how you can do,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not only MAC Filter can help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 06:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846924#M24823</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-04-29T06:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846974#M24827</link>
      <description>&lt;HR /&gt;&lt;P&gt;hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322101" target="_self"&gt;&lt;SPAN class=""&gt;Dennis Mink&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I know.&lt;/P&gt;&lt;P&gt;But I'm asking how can I restrict the user. When they change their physical port, their device will not be authenticated.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 08:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846974#M24827</guid>
      <dc:creator>mortezasadeghi</dc:creator>
      <dc:date>2019-04-29T08:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846977#M24831</link>
      <description>&lt;P&gt;We have Cisco ACS&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 08:12:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3846977#M24831</guid>
      <dc:creator>mortezasadeghi</dc:creator>
      <dc:date>2019-04-29T08:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3847143#M24835</link>
      <description>You have a couple of options. The easy thing would be to do port security on the physical interface. However, port security &amp;amp; 8021x typically are not the best when playing together and in my opinion most people would say not to use both together. You could have your policy server deploy policy as you would with ISE or ACS. I think in order to meet your requirement you could eliminate relying on ISE/ACS and statically configure your one port for you one host with whatever policy you want to include vlan etc. You could then configure the other ports on the switch to use policy from AAA server &amp;amp; ensure the one host you do not want to migrate is not a part of any groups on the AAA server so even if the host moved from one interface to another it would fail authentication/authorization and no longer be on the network.</description>
      <pubDate>Mon, 29 Apr 2019 13:05:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-authentication/m-p/3847143#M24835</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-04-29T13:05:49Z</dc:date>
    </item>
  </channel>
</rss>

