<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic fixed ip devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449114#M569030</link>
    <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In 802.1x/mac bypass how are devices with statically assigned ip address taken care of?&lt;/P&gt;&lt;P&gt;we have some badge/id code readers that have static ip over ethernet. What will the cisco switch port config look like for this case, will it need a default vlan on it? Or can that port be just enabled for mab/802.1but vlan remains to the device's static ip?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;preferably doing profile is being looked upon rather than having a mac bypass list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 14:26:56 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2021-08-13T14:26:56Z</dc:date>
    <item>
      <title>fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449114#M569030</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In 802.1x/mac bypass how are devices with statically assigned ip address taken care of?&lt;/P&gt;&lt;P&gt;we have some badge/id code readers that have static ip over ethernet. What will the cisco switch port config look like for this case, will it need a default vlan on it? Or can that port be just enabled for mab/802.1but vlan remains to the device's static ip?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;preferably doing profile is being looked upon rather than having a mac bypass list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 14:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449114#M569030</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2021-08-13T14:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449197#M569033</link>
      <description>&lt;P&gt;These device can not installed suplicant , they need to go MAB authentication here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look at the thread may help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-static-ip-assigned-devices-problem/m-p/4000705" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-static-ip-assigned-devices-problem/m-p/4000705&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 16:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449197#M569033</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-13T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449934#M569055</link>
      <description>&lt;P&gt;Yes, these devices are not supporting 802.1x. with MAB being used for them, do the switch port configurations need to have a default or not-the-final vlan or it should be left to the actual vlan that needs to be allowed?&lt;/P&gt;&lt;P&gt;If profile is to be done on ISE, can the profile be done with out the port having access?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 13:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4449934#M569055</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2021-08-16T13:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450035#M569058</link>
      <description>&lt;P&gt;We use MAB for a lot of devices and some with static IPs. All of our ports are standard PC ports. When mab kicks in, we will usually change the vlan and send down a dACL. Since the device is static, the IP won't work when on the PC vlan, but will be fine once you switch vlans. This works good for devices that can't detect a vlan change and restart DHCP also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently use this method for a lot of printers etc. that can't do 802.1x and we don't want thousands of static switchports to manage.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 16:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450035#M569058</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2021-08-16T16:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450223#M569066</link>
      <description>&lt;P&gt;Thanks Dustin.&lt;/P&gt;&lt;P&gt;For the static ones, do you employ profiles to gather make or model? Or is it just permitted on dacl?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 01:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450223#M569066</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2021-08-17T01:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450695#M569088</link>
      <description>&lt;P&gt;we only profile wireless devices so we know where to send them. For MAB, we use AD groups, so by checking group membership, we know what they are and where they go. We tried to stay away from profiling as that uses more licensing, so ends up as an added expense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's part of all ours, we currently have 13 groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=AccessPoints,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=LaserPrinters,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=ThermalPrinters,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=StaticTesters,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=AV,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=SecurityCameras,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=External,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=RoomKits,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=PDCSensors,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=Wi_phone,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=Wi_scanner,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=Wi_internal,OU=Groups,OU=Devices MAC Authenticated,&lt;BR /&gt;CN=Wi_external,OU=Groups,OU=Devices MAC Authenticated,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 18:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4450695#M569088</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2021-08-17T18:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4451864#M569143</link>
      <description>&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;there is no AD groups for us. any ideas on profiling ?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 13:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4451864#M569143</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2021-08-19T13:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: fixed ip devices</title>
      <link>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4451909#M569145</link>
      <description>&lt;P&gt;not sure what info you will initially get for profiling especially if it's static IP, so no DHCP profiling. You may only get profiling by the OUI of the mac. This may be enough as it is usually manufacturer specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option may be to make groups for the endpoints, but that would require you to pre-populate a list of the mac addresses. You could then call those groups in the rules. Here's an old link on endpoint identity groups. This really depends on the scale you are working as it can be a bit of a manual process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html#wp1152159" target="_blank" rel="noopener"&gt;https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html#wp1152159&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 14:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fixed-ip-devices/m-p/4451909#M569145</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2021-08-19T14:53:30Z</dc:date>
    </item>
  </channel>
</rss>

