<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.3 Newbie in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884539#M371449</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking at setting up a Cisco ACS 5.3 for MAC address based VLANs on a 2960 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as anyone done this before? Basiacally what I want is &lt;/P&gt;&lt;P&gt;1. Have a list of devices specified in the ACS with their MAC address&lt;/P&gt;&lt;P&gt;2. Connect the swicth to the ACS&lt;/P&gt;&lt;P&gt;3. When a device is plugged in, the swicth should check with the ACS onto whcih VLAN the host should be on,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:03:17 GMT</pubDate>
    <dc:creator>cisco-cit</dc:creator>
    <dc:date>2019-03-11T02:03:17Z</dc:date>
    <item>
      <title>Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884539#M371449</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking at setting up a Cisco ACS 5.3 for MAC address based VLANs on a 2960 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as anyone done this before? Basiacally what I want is &lt;/P&gt;&lt;P&gt;1. Have a list of devices specified in the ACS with their MAC address&lt;/P&gt;&lt;P&gt;2. Connect the swicth to the ACS&lt;/P&gt;&lt;P&gt;3. When a device is plugged in, the swicth should check with the ACS onto whcih VLAN the host should be on,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884539#M371449</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2019-03-11T02:03:17Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884540#M371481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I guess that step 2 should say "connect the host to the switch".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you be more specific on what you're trying to achieve ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2012 03:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884540#M371481</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-05-13T03:19:08Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884541#M371538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Effectively what I want is to have a list of known device(laptops/desktops) mac addresses stored on the ACS.&lt;/P&gt;&lt;P&gt;When a device is connected to a switch it should talk to the ACS and check if the mac address is known. The ACS should also tell the switch which VLAN to put it into.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how to make the switch talk to ACS when a device is plugged into a port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2012 23:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884541#M371538</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2012-05-13T23:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884542#M371585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ACS you should configure to authenticate using "Internal Hosts" (which is the mac address database) and to authorize by using "authentication profiles" (this is where you configure what VLAN to use)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are starting I will recommend you to test only authentication. Then if everything is all right you can add the authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ON the switch side you will need to configure something like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius-server host x.x.x.x key PASSWORD&lt;BR /&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;aaa group server radius ACS&lt;BR /&gt;server x.x.x.x&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group ACS&lt;BR /&gt;aaa authorization network default group ACS &lt;BR /&gt;aaa accounting dot1x default start-stop group ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernetX/X&lt;BR /&gt;&amp;nbsp; mab&lt;BR /&gt;&amp;nbsp; authentication order mab&lt;BR /&gt;&amp;nbsp; authentication port-control auto&lt;BR /&gt;&amp;nbsp; dot1x pae authenticator&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Please rate if it helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 02:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884542#M371585</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-05-15T02:08:39Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884543#M371622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant see what youhave posted about the switch though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 02:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884543#M371622</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2012-05-15T02:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884544#M371667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mate,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the switch I dont apper to have the mab command in interfaces..&lt;/P&gt;&lt;P&gt;It comes up on some other switches though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also not been able to see where to link " authentication profiles" to "hosts"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 05:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884544#M371667</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2012-05-25T05:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884545#M371736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok got it working to a certain extent. &lt;/P&gt;&lt;P&gt;I have internal hosts and I have managed to get them to get network access with an Authorization Profile which gives them access and puts them in a VLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next question is how can I get different host groups to use different Authorization profiles?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 00:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884545#M371736</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2012-06-01T00:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 Newbie</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884546#M371783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Ok got it working to a certain extent. &lt;/P&gt;&lt;P&gt;I&amp;nbsp; have internal hosts and I have managed to get them to get network&amp;nbsp; access with an Authorization Profile which gives them access and puts&amp;nbsp; them in a VLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next question is how can I get different host groups to use different Authorization profiles?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 00:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-newbie/m-p/1884546#M371783</guid>
      <dc:creator>cisco-cit</dc:creator>
      <dc:date>2012-06-01T00:54:25Z</dc:date>
    </item>
  </channel>
</rss>

