<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic uplink endpoint in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446493#M568936</link>
    <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;Apart from ISE taking care of endpoint security, can it be used by any means to secure switch uplink ports or ports where servers may be connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Aug 2021 14:50:31 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2021-08-09T14:50:31Z</dc:date>
    <item>
      <title>uplink endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446493#M568936</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;Apart from ISE taking care of endpoint security, can it be used by any means to secure switch uplink ports or ports where servers may be connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446493#M568936</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2021-08-09T14:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: uplink endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446533#M568937</link>
      <description>&lt;P&gt;yes can be done profiling using ISE. ( you can segment Server connected ports).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446533#M568937</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-09T15:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: uplink endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446800#M568943</link>
      <description>&lt;P&gt;What kind of security are you looking to provide for uplink ports? NAC is mainly intended to secure switchport connections that are patched out to the floor and accessible from common users (or threat actors that gain access to the floor). It is not intended to provide security for switch uplinks that are typically physically secured behind locked doors in a comms room.&lt;/P&gt;
&lt;P&gt;Server operating systems typically have limited support for active authentication protocols like 802.1x, so you're limited to using MAC-based authentication (which is easily spoofed). Profiling might be possible, but servers do not typically provide much unique information to the network that can be used by profiling to provide any effective level of security. I normally recommend customers move any servers they have on the floor to a virtual environment that cannot easily be physically accessed by a normal user or threat actor.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 22:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/uplink-endpoint/m-p/4446800#M568943</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-08-09T22:42:55Z</dc:date>
    </item>
  </channel>
</rss>

