<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE switch configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799005#M41758</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have got the following network in brief:&lt;/P&gt;
&lt;P&gt;Devices -&amp;gt; Access Switch -&amp;gt; Core Switch -&amp;gt; Access Switch -&amp;gt; ISE Server&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All switches are IOS capable for the 802.1X and AAA configurations for ISE to manage the network devices. However, I have read through guide on the switches configuration in preparation for CIsco ISE deployment but I am just wondering do I need to configure both access switches and Core switches or do I only configure the access switches for ISE?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your time reading!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:15:31 GMT</pubDate>
    <dc:creator>Marcus Peck</dc:creator>
    <dc:date>2019-03-11T06:15:31Z</dc:date>
    <item>
      <title>Cisco ISE switch configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799005#M41758</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have got the following network in brief:&lt;/P&gt;
&lt;P&gt;Devices -&amp;gt; Access Switch -&amp;gt; Core Switch -&amp;gt; Access Switch -&amp;gt; ISE Server&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All switches are IOS capable for the 802.1X and AAA configurations for ISE to manage the network devices. However, I have read through guide on the switches configuration in preparation for CIsco ISE deployment but I am just wondering do I need to configure both access switches and Core switches or do I only configure the access switches for ISE?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your time reading!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799005#M41758</guid>
      <dc:creator>Marcus Peck</dc:creator>
      <dc:date>2019-03-11T06:15:31Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799006#M41759</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;To authenticate clients you only need to configure the device (NAS)&amp;nbsp;that will be passing the radius packet to your ISE (radius server) often secured by way of a mutually configured secret key on both devices (authenticator and the authentication&amp;nbsp;server)&amp;nbsp;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;An example of a NAS would be access switch, WLC.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2015 11:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799006#M41759</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2015-11-20T11:04:26Z</dc:date>
    </item>
    <item>
      <title>Hi Marcus,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799007#M41760</link>
      <description>&lt;P&gt;Hi Marcus,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It depends on your network design. If all the endpoints gets connected to access switch only, then the major piece of configuration goes on the access switch. Depending on our profiling setup on ISE, if you are using a DHCP profiling option, then you need to ensure that the ISE PSN IP or virtual IP (if Load balanced), is configured as a IP helper on the L3 SVI which might be on your Core switch.&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vivek&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2015 03:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799007#M41760</guid>
      <dc:creator>Vivek Ganapathi</dc:creator>
      <dc:date>2015-11-23T03:34:19Z</dc:date>
    </item>
    <item>
      <title>Hi Vivek,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799008#M41761</link>
      <description>Hi Vivek,
thanks for your reply. The reason I asked this question is because I do not know if the L3 core needs any sort of configuration for the profiling and the NAC to work on the access layer switches connected to it? All endpoints are connected to the access switches as pointed out in my first post and all endpoints are non-dhcp clients. 
I do know that the Access switches needs to be configured accordingly but how about those switches without any endpoints (e.g. Core switches and distribution)?</description>
      <pubDate>Mon, 23 Nov 2015 03:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799008#M41761</guid>
      <dc:creator>Marcus Peck</dc:creator>
      <dc:date>2015-11-23T03:56:29Z</dc:date>
    </item>
    <item>
      <title>If all the clients are non</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799009#M41762</link>
      <description>&lt;P&gt;If all the clients are non-DHCP clients, then there is no configuration on core or distribution at all.&lt;/P&gt;
&lt;P&gt;But you may need to look out for different profiling options if the clients are not DHCP enabled. Does the access switch support IOS sensor function? Would be very useful to have one as it would send important profiling information to ISE. You may need to use a right profiling options for ISE to determine the endpoint details.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vivek&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2015 04:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-switch-configuration/m-p/2799009#M41762</guid>
      <dc:creator>Vivek Ganapathi</dc:creator>
      <dc:date>2015-11-23T04:14:44Z</dc:date>
    </item>
  </channel>
</rss>

