<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - Securing witch port channel interfaces in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143206#M562582</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my switch, I have all the switchports configured with ISE- 802.X. My question is how can I secure the interfaces that belongs to a channel-group ? Someone can easily unplug the port and plug in any device, and since there is not security on the port that may allow the device to connect to the network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;SW-C3850#&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/48&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW-C3850#&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/48&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !!!&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 17:58:46 GMT</pubDate>
    <dc:creator>BigK</dc:creator>
    <dc:date>2020-08-28T17:58:46Z</dc:date>
    <item>
      <title>ISE - Securing witch port channel interfaces</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143206#M562582</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my switch, I have all the switchports configured with ISE- 802.X. My question is how can I secure the interfaces that belongs to a channel-group ? Someone can easily unplug the port and plug in any device, and since there is not security on the port that may allow the device to connect to the network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;SW-C3850#&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/48&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW-C3850#&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/48&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !!!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 17:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143206#M562582</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2020-08-28T17:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Securing witch port channel interfaces</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143245#M562583</link>
      <description>&lt;P&gt;In terms of Security - we need to understand as below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Physical Security&lt;/P&gt;
&lt;P&gt;2. Network Security&lt;/P&gt;
&lt;P&gt;3. Layer Security ---so on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the Physical security breached - no one can help - it is a disaster - intruder can do anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;coming back to your question - This port is part of Port-channel - so what will happen when the end-user device connected?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 19:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143245#M562583</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-08-28T19:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Securing witch port channel interfaces</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143307#M562586</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is the question -&lt;SPAN&gt;&amp;nbsp;what will happen when the end-user device is connected to one of these ports?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 22:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-securing-witch-port-channel-interfaces/m-p/4143307#M562586</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2020-08-28T22:18:49Z</dc:date>
    </item>
  </channel>
</rss>

