<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limiting Device Movement using MAC Address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878706#M547805</link>
    <description>&lt;P&gt;follow the other post as suggested. let us know if you need any further assitance.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2019 18:25:15 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-06-24T18:25:15Z</dc:date>
    <item>
      <title>Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878306#M547799</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Is it possible to limit device movement using MAC address? In this case, I want to limit IP phone's movement. The definition of movement is, I want a certain IP phone to connect on a certain switch port. Let's say IP phone A can only connect to Switch A port 1, while IP phone B can only connect to Switch B port 10.&amp;nbsp;IP phone will use voice VLAN while access VLAN also configured on the port, so any user can use the extension port on the back of the IP phone.&lt;/P&gt;&lt;P&gt;I already managed to limit the movement, but only on 1 switch. If I move those IP phones to different switch, the policy will not take effect. The question would be, can I do it centrally? So I do not have to adjust the configuration on every switch. The command would be a long one since I have more than 50 IP phones on deployment with more than 10 switches to be configured. Below is the example of my current command:&lt;/P&gt;&lt;P&gt;mac address-table static 1234.5678.ABCD vlan 10 int te3/0/13&lt;BR /&gt;mac address-table static&amp;nbsp;ABCD.EFGH.1234 vlan 10 drop&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878306#M547799</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2020-02-21T19:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878326#M547800</link>
      <description>&lt;P&gt;Are you using RADIUS server like ISE or ACS? Using ISE/ACS will let you manage policy centrally regardless of where IP Phone connects.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 07:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878326#M547800</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-06-24T07:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878335#M547801</link>
      <description>&lt;P&gt;Adding to other post&lt;/P&gt;
&lt;P&gt;You have 2 options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Option 1 , you need to have centralised identity system which can take care of the policies.&lt;/P&gt;
&lt;P&gt;Option2. you need to do manually all over device(which is time consume for adding and removing)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion to have Option1 (look for option in the market)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 07:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878335#M547801</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-06-24T07:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878351#M547802</link>
      <description>&lt;P&gt;Hi howon,&lt;/P&gt;&lt;P&gt;Yes, I'm using ISE v2.3.&lt;/P&gt;&lt;P&gt;From Live Log authentication detail, I saw switch name, switch IP address, and device mac address. But I did not see source port from the switch on the log detail.&amp;nbsp;Can I also set the source port on ISE?&lt;BR /&gt;I'm thinking to define the incoming switch address on ISE, but I also set the MAC limitation on local switch, since I did not see any port-like attributes on ISE. Do you think this will work? I will be working on this idea on my environment.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 08:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878351#M547802</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2019-06-24T08:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878353#M547803</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;&lt;P&gt;I have ISE 2.3 installed. On ISE, I should be working on Policy Sets menu, right? Or somewhere else?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 08:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878353#M547803</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2019-06-24T08:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878498#M547804</link>
      <description>&lt;P&gt;Create two custom attributes; one for NAD IP and another for Interface name&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to Administration &amp;gt; Identity Management &amp;gt; Settings &amp;gt; Endpoint Custom Attributes&lt;/LI&gt;
&lt;LI&gt;Create two attributes called 'NAD' and 'Interface' with String data type&lt;/LI&gt;
&lt;LI&gt;Go to Context visibility for each of the IP Phone MAC address and fill on the NAD IP and Interface name in the newly created attribute&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Create Policy rule for MAB that uses following condition:&lt;/P&gt;
&lt;P&gt;RADIUS:NAS-IP-Address(4) == ENDPOINT:NAD&lt;BR /&gt;&amp;amp;&lt;/P&gt;
&lt;P&gt;RADIUS:NAS-Port-ID(87) == ENDPOINT:Interface&lt;/P&gt;
&lt;P&gt;And assign voice domain permission&lt;/P&gt;
&lt;P&gt;Above should be enough to lock-in the specific IP phones to specific NAD + Interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basic idea is same as the instructions in the following link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/dynamic-attribute-with-ise-mac-address-matching/ta-p/3643882" target="_blank"&gt;https://community.cisco.com/t5/security-documents/dynamic-attribute-with-ise-mac-address-matching/ta-p/3643882&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 12:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878498#M547804</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-06-24T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Device Movement using MAC Address</title>
      <link>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878706#M547805</link>
      <description>&lt;P&gt;follow the other post as suggested. let us know if you need any further assitance.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 18:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limiting-device-movement-using-mac-address/m-p/3878706#M547805</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-06-24T18:25:15Z</dc:date>
    </item>
  </channel>
</rss>

