<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Pre-Auth ACL vs No Pre-Auth ACL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3988473#M541151</link>
    <description>&lt;P&gt;Without "authentication open" you are running "closed mode" and the switchport will only allow EAP packets and no user-packets. You need the ACL if you want to operate your switchports in "low-impact-mode" which is quite likely that you want it. But you would not start with it from the beginning. You typically begin with monitor-mode ("authentication open", no Pre-Auth-ACL and the ISE does not send any ACL to the switch) and move later to low-impact-mode ("authentication open", Pre-Auth-ACL and the ISE replaces the ACL with the right one depending on the device/user).&lt;/P&gt;</description>
    <pubDate>Sun, 24 Nov 2019 11:30:29 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2019-11-24T11:30:29Z</dc:date>
    <item>
      <title>ISE Pre-Auth ACL vs No Pre-Auth ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3987927#M541150</link>
      <description>&lt;P&gt;A quick question about Pre-Auth ACLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently deploying ISE 2.4 for wired 802.1x/MAB.&amp;nbsp; I do NOT have 'authentication open' on the switchports.&amp;nbsp; I do have a monitor mode MAB policy to permit access on the default authZ rule for now until I get all my profile's identified and whatnot.&amp;nbsp; I will deploy TrustSec after i get the profiling process completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is this.&amp;nbsp; If I do NOT have a pre-auth ACL does this mean the clients have NO access or ALL access while authenticating?&amp;nbsp; I have 802.1x/MAB priority and order on the switchports.&amp;nbsp; Is the Pre-Auth ACL a must-have?&amp;nbsp; What are use-cases to have/not have one and the access results of the clients because of the ACL existing/not-existing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 15:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3987927#M541150</guid>
      <dc:creator>zsmithtek</dc:creator>
      <dc:date>2019-11-22T15:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Pre-Auth ACL vs No Pre-Auth ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3988473#M541151</link>
      <description>&lt;P&gt;Without "authentication open" you are running "closed mode" and the switchport will only allow EAP packets and no user-packets. You need the ACL if you want to operate your switchports in "low-impact-mode" which is quite likely that you want it. But you would not start with it from the beginning. You typically begin with monitor-mode ("authentication open", no Pre-Auth-ACL and the ISE does not send any ACL to the switch) and move later to low-impact-mode ("authentication open", Pre-Auth-ACL and the ISE replaces the ACL with the right one depending on the device/user).&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 11:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3988473#M541151</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-11-24T11:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Pre-Auth ACL vs No Pre-Auth ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3988977#M541152</link>
      <description>please check out wired guide &lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;</description>
      <pubDate>Mon, 25 Nov 2019 15:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pre-auth-acl-vs-no-pre-auth-acl/m-p/3988977#M541152</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-25T15:35:45Z</dc:date>
    </item>
  </channel>
</rss>

