<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: any difference in ISE for open and closed mode in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956456#M455779</link>
    <description>&lt;P&gt;Perhaps other can point out further subtleties on this, but I would say that if the switch port is in Closed Mode, then any Auth Failure from the RADIUS server would result in the port being closed (client data access denied).&lt;/P&gt;
&lt;P&gt;Therefore you can run an ISE Report - "RADIUS Authentications", and filter on RADIUS Status "Failed".&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2019 02:49:28 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2019-11-11T02:49:28Z</dc:date>
    <item>
      <title>any difference in ISE for open and closed mode</title>
      <link>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956453#M455778</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently activating monitor mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i checked in Context visibility, some devices have Auth failure reason such as &lt;SPAN&gt;Rejected per authorization profile&lt;/SPAN&gt;, subject nt found in identity stores,etc.&lt;/P&gt;&lt;P&gt;When activating closed mode, does this means tht these objects will be blocked? Can i tell from the "Auth failure reason" which devices will be blocked after "closed mode" activation?&lt;/P&gt;&lt;P&gt;Wht is the best practice to see if a device pass/blocked after "closed mode" activation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 02:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956453#M455778</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-11-11T02:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: any difference in ISE for open and closed mode</title>
      <link>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956456#M455779</link>
      <description>&lt;P&gt;Perhaps other can point out further subtleties on this, but I would say that if the switch port is in Closed Mode, then any Auth Failure from the RADIUS server would result in the port being closed (client data access denied).&lt;/P&gt;
&lt;P&gt;Therefore you can run an ISE Report - "RADIUS Authentications", and filter on RADIUS Status "Failed".&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 02:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956456#M455779</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-11T02:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: any difference in ISE for open and closed mode</title>
      <link>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956478#M455780</link>
      <description>&lt;P&gt;Hi Arne,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI authentication policy is ALLOW all for all "internal endpoints" which means all endpoints.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;RADIUS Status "Failed"&amp;nbsp; here means authorization failure?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can see there are only 2 types of situation tht will hv&amp;nbsp;RADIUS Status "Failed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1)Those non 802.1X devices tht uses MAB but its mac address not added into the customize identity grp:laptop-mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2)Those 802.1x devices tht has auth failure reason: devices not falls under applicable identity stores-which i still checking out why&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 04:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/any-difference-in-ise-for-open-and-closed-mode/m-p/3956478#M455780</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-11-11T04:09:53Z</dc:date>
    </item>
  </channel>
</rss>

