<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x with DELL IDRAC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279520#M565015</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;In general, NAC is used in the access layer, i.e. end users. It's not used&lt;BR /&gt;usually in servers unless there are special uses.&lt;BR /&gt;&lt;BR /&gt;IDRAC don't have dot1x supplicant. It should be using MAB. If the IDRAC is&lt;BR /&gt;having a static IP and not DHCP, the DACL won't be applied cuz device&lt;BR /&gt;tracking can't get the IP address using DHCP. It will try to get it using&lt;BR /&gt;ARP which will take time until ARP update is requested which can take 4&lt;BR /&gt;hours.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Tue, 26 Jan 2021 07:06:20 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2021-01-26T07:06:20Z</dc:date>
    <item>
      <title>Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279183#M564989</link>
      <description>&lt;P&gt;I am having issues configuring dot1x/mab protocols for my DELL iDRACs. I was hoping to find some support for doing this. I currently have the idracs failing authentication in the RADIUS live logs, meaning that my policy set could be set incorrectly. I have my idrac's setup in an Endpoint Identity Group but I still cannot get the MAB protocol to take over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have experience doing this with the Dell iDRACs?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 18:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279183#M564989</guid>
      <dc:creator>JackFlannery9379</dc:creator>
      <dc:date>2021-01-25T18:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279386#M565006</link>
      <description>&lt;P&gt;This should just a standard MAB transaction just like any other endpoint.&amp;nbsp; Does your switch and switchport config work for other MAB endpoints?&amp;nbsp; What is the NAD?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 23:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279386#M565006</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2021-01-25T23:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279393#M565007</link>
      <description>&lt;P&gt;can we see your SW config ?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 23:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279393#M565007</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-25T23:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279520#M565015</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;In general, NAC is used in the access layer, i.e. end users. It's not used&lt;BR /&gt;usually in servers unless there are special uses.&lt;BR /&gt;&lt;BR /&gt;IDRAC don't have dot1x supplicant. It should be using MAB. If the IDRAC is&lt;BR /&gt;having a static IP and not DHCP, the DACL won't be applied cuz device&lt;BR /&gt;tracking can't get the IP address using DHCP. It will try to get it using&lt;BR /&gt;ARP which will take time until ARP update is requested which can take 4&lt;BR /&gt;hours.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 26 Jan 2021 07:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279520#M565015</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-26T07:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279871#M565018</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get your point, but device tracking should send an ARP probe in order to get an IP to MAC tracking. For sure device tracking has various configurations under different switch platforms.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1156142"&gt;@JackFlannery9379&lt;/a&gt;can you please share the output of the interface configuration from the switch port where iDRAC is connected?&lt;/P&gt;&lt;P&gt;Also as you said your iDRAC devices are failing authentication meaning that the get an access denied response? If that's true then you must review your policies and make sure that you used the proper Identity group options under your MAB authorization policy.&lt;/P&gt;&lt;P&gt;Regardless of static IP or not, 802.1x/MAB request should get an access accept message if your policy is configured correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 16:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4279871#M565018</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2021-01-26T16:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4280152#M565037</link>
      <description>&lt;P&gt;You have not provided information about any specifics about ISE error messages, your authorization rules, what network device, network device configuration so it is hard to provide suggestions.&lt;/P&gt;
&lt;P&gt;Please see &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt; for best practice wired configuration examples.&lt;/P&gt;
&lt;P&gt;Also see &lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_self"&gt;How to Ask The Community for Help&lt;/A&gt;&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 23:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4280152#M565037</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-01-26T23:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x with DELL IDRAC</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4280284#M565045</link>
      <description>+5 &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321962"&gt;@Panos Bouras&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;What you mentioned is correct in theory but not always in practice. When&lt;BR /&gt;the ARP packets are sent to devices with static IPs (like ILO or iDRAC),&lt;BR /&gt;the source IP will be 0.0.0.0. Even though the source is not relevant,&lt;BR /&gt;these devices won't respond back. This is a known issue.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2018/pdf/BRKDGT-2601.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2018/pdf/BRKDGT-2601.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There are workarounds in the above link but they don't necessarily work on&lt;BR /&gt;all switches. Hence was my response. The devices with DHCP enabled are good&lt;BR /&gt;because the source of tracking will be DHCP. For static IPs will be an&lt;BR /&gt;issue. It might be a different problem so let's see the config. But when&lt;BR /&gt;static IP was mentioned, it popped in my head at first glance.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Jan 2021 06:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-with-dell-idrac/m-p/4280284#M565045</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-27T06:19:20Z</dc:date>
    </item>
  </channel>
</rss>

