<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unique NAC Solution using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449638#M537348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work without any control on access switches?  Customer wants the solution to work with end user machines only and ise being deployed at data center&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The branch network is not under his control&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Oct 2016 13:55:26 GMT</pubDate>
    <dc:creator>Hemant Bharati</dc:creator>
    <dc:date>2016-10-13T13:55:26Z</dc:date>
    <item>
      <title>Unique NAC Solution using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449636#M537345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My customer is a Core Banking Solution provider they manage the DC service and the branches are managed by Banks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is looking for NAC solution which can be implemented in the DC without touching the branches.&lt;/P&gt;&lt;P&gt;I am looking for pointers on how can we use ISE to only allow domain Users on authorized machines only.&lt;/P&gt;&lt;P&gt;All other personal or unauthorized laptops to be blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;Branches have only wired network&lt;/LI&gt;&lt;LI&gt;Branches have ISR800M routers &lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2016 20:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449636#M537345</guid>
      <dc:creator>Hemant Bharati</dc:creator>
      <dc:date>2016-10-11T20:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unique NAC Solution using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449637#M537346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use AD as the ID sources and check AD group memberships to allow only domain users. Use ISE profiling and/or ISE posture to enforce on authorized machines. If Windows, then it's possible to use EAP Chaining to check both user and machine identities via EAP-FAST. Another option is to use CWA chaining.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2016 13:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449637#M537346</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-10-13T13:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unique NAC Solution using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449638#M537348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work without any control on access switches?  Customer wants the solution to work with end user machines only and ise being deployed at data center&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The branch network is not under his control&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2016 13:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449638#M537348</guid>
      <dc:creator>Hemant Bharati</dc:creator>
      <dc:date>2016-10-13T13:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unique NAC Solution using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449639#M537350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please see the latest &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/compatibility/ise_sdt.html"&gt;&lt;STRONG&gt;ISE Compatibility Guide&lt;/STRONG&gt;&lt;/A&gt; for supported network access devices.&lt;/P&gt;&lt;P&gt;ISR 8xx have relatively poor ISE feature support on switchports beyond basic 802.1X and TrustSec:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="9" rowspan="1"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="1" rowspan="2"&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231102"&gt;&lt;/A&gt;ISR 88x, 89x Series&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231104"&gt;&lt;/A&gt;IOS 15.3.2T(ED)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231106"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; √ &lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231108"&gt;&lt;/A&gt;&lt;STRONG class="cBold"&gt; !&lt;/STRONG&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231110"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; X&lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231112"&gt;&lt;/A&gt;&lt;STRONG class="cBold"&gt; !&lt;/STRONG&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231114"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; X&lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231116"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; X&lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-231118"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; √ &lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they don't own/manage the ISR800's it doesn't really matter since you will have no way to configure and manage the endpoint at the edge&amp;nbsp;&amp;nbsp; 8-(&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Oct 2016 21:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unique-nac-solution-using-ise/m-p/3449639#M537350</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-10-17T21:19:51Z</dc:date>
    </item>
  </channel>
</rss>

