<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication first before DHCP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514960#M518568</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi chyps,&lt;/P&gt;&lt;P&gt;Do you have link or manual I can refer to apply the information you said?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jan 2018 02:10:33 GMT</pubDate>
    <dc:creator>rhuel.phils</dc:creator>
    <dc:date>2018-01-18T02:10:33Z</dc:date>
    <item>
      <title>Authentication first before DHCP</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514958#M518564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, In our current deployment we allow endpoint to get IP address then it will authenticate.&lt;/P&gt;&lt;P&gt;is it possible we first allow the device to authenticate then after successful auth they will&lt;/P&gt;&lt;P&gt;get IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one test this scenario?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 07:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514958#M518564</guid>
      <dc:creator>rhuel.phils</dc:creator>
      <dc:date>2018-01-17T07:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication first before DHCP</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514959#M518566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on auth type.&amp;nbsp; Using 802.1X, it is certainly possible to authenticate via L2 protocol and then allow access to DHCP after successful authentication.&amp;nbsp; This is definitely the case in closed mode where endpoint has no access until auth successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For MAB, it is also possible to first authenticate/authorize MAC address prior to IP address assignment.&amp;nbsp; Of course, it is not possible to perform web authentication until IP address received.&amp;nbsp; This is why a typical CWA policy will allow DHCP and set redirect as the result of MAC auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS Accounting Interim Update with notify ISE if IP address received after initial authentication and Accounting Start sent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 17:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514959#M518566</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-01-17T17:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication first before DHCP</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514960#M518568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi chyps,&lt;/P&gt;&lt;P&gt;Do you have link or manual I can refer to apply the information you said?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 02:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514960#M518568</guid>
      <dc:creator>rhuel.phils</dc:creator>
      <dc:date>2018-01-18T02:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication first before DHCP</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514961#M518570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-68149"&gt;How To: ISE Phased Deployments&lt;/A&gt; and &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-68153"&gt;How To: Deploy ISE in Closed Mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and Cisco Live BRKSEC-2691&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Wireless, it requires auth first before DHCP, unless the WLAN setup in open mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 06:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-first-before-dhcp/m-p/3514961#M518570</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-18T06:41:43Z</dc:date>
    </item>
  </channel>
</rss>

