<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C3PL Templet For 802.1X wired in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577759#M573649</link>
    <description>&lt;P&gt;&lt;SPAN&gt;my question is which parameter should I remove from the temple to allow only DOR.1X&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-FYSA for testing purposes and actually best practice from Cisco, you should configure a single port using IBNS1.0 with your specific/desired commands, test the one port, and transition to IBNS2.0 via #authentication display new-style once you are satisfied with the configuration.&amp;nbsp; This should help achieve the most accurate IBNS2.0 config to meet your needs.&amp;nbsp; To determine what mode you are running: #authentication display config-mode.&amp;nbsp; A quick peek at the above config you would want to remove any mab references.&amp;nbsp; However, you would want to make sure that you have some sort of reauth timer and/or some event for auth failure which it looks like you are attempting&amp;nbsp;to accomplish too so that is good.&amp;nbsp; Lastly, your 2.0 config can/should be derived from 1.0 migration tool &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2022 12:08:57 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2022-03-24T12:08:57Z</dc:date>
    <item>
      <title>C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577737#M573644</link>
      <description>&lt;P&gt;Hello everyone ;&lt;/P&gt;&lt;P&gt;actually, I'm using&amp;nbsp;C3PL Templet For 802.1X wired, I'm using first-order dot1.X and MAB.&lt;/P&gt;&lt;P&gt;my new use case is That I'm planning to use that to apply only DOT.1X as authentication, so I believe that I need to create a new temple and assign it to specific port that I went to apply only&amp;nbsp;DOT.1X.&lt;/P&gt;&lt;P&gt;my question is which parameter should I remove from the temple to allow only DOR.1X&lt;/P&gt;&lt;P&gt;below is the template that I'm using.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;class-map type control subscriber match-any AAA-DOWN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;match result-type aaa-timeout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;class-map type control subscriber match-all DOT1X-FAILED&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;match method dot1x&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;match result-type method dot1x authoritative&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;policy-map type control subscriber DOT1X-DEFAULT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;event session-started match-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 class always do-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 authenticate using dot1x priority 10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;20 authenticate using mab priority 20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;event violation match-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 class always do-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 restrict&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;event agent-found match-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 class always do-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 authenticate using dot1x&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;event authentication-failure match-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 class AAA-DOWN do-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 authorize&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;20 activate service-template CRITICAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;30 terminate dot1x&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;40 terminate mab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;20 class DOT1X-FAILED do-all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 authenticate using mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thank's in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 11:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577737#M573644</guid>
      <dc:creator>ezzaariyouness</dc:creator>
      <dc:date>2022-03-24T11:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577755#M573648</link>
      <description>&lt;P&gt;C3PL Templet is originally designed to help cisco switch. &amp;nbsp;C3PL Templet is a secure 802.1X solution. &amp;nbsp;It is a great security solution that helps you to control VLAN and high user security with one policy. But the problem is C3PL Templet doesn't work on all the switches. So, to resolve the problem we need to configure 802.1X on a Cisco switch. Here is the complete guide for that&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577755#M573648</guid>
      <dc:creator>duckjoser227</dc:creator>
      <dc:date>2022-03-24T12:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577759#M573649</link>
      <description>&lt;P&gt;&lt;SPAN&gt;my question is which parameter should I remove from the temple to allow only DOR.1X&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-FYSA for testing purposes and actually best practice from Cisco, you should configure a single port using IBNS1.0 with your specific/desired commands, test the one port, and transition to IBNS2.0 via #authentication display new-style once you are satisfied with the configuration.&amp;nbsp; This should help achieve the most accurate IBNS2.0 config to meet your needs.&amp;nbsp; To determine what mode you are running: #authentication display config-mode.&amp;nbsp; A quick peek at the above config you would want to remove any mab references.&amp;nbsp; However, you would want to make sure that you have some sort of reauth timer and/or some event for auth failure which it looks like you are attempting&amp;nbsp;to accomplish too so that is good.&amp;nbsp; Lastly, your 2.0 config can/should be derived from 1.0 migration tool &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577759#M573649</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-03-24T12:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577807#M573652</link>
      <description>&lt;P&gt;Hi Mike ;&lt;/P&gt;&lt;P&gt;I'm confused about your reply. how can I perform dot1.X&amp;nbsp; without MAB using&amp;nbsp;&lt;SPAN&gt;C3PL Templet .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;note that is not possible to configure DOT1.X directly on the port&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Younes&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 13:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4577807#M573652</guid>
      <dc:creator>ezzaariyouness</dc:creator>
      <dc:date>2022-03-24T13:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4578489#M573682</link>
      <description>&lt;P&gt;If your goal is to only do DOT1X you would have to remove these two lines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;20 authenticate using mab priority 20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;40 terminate mab&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 12:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4578489#M573682</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2022-03-25T12:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4590443#M574063</link>
      <description>&lt;P&gt;The &lt;LI-MESSAGE title="ISE Secure Wired Access Prescriptive Deployment Guide" uid="3641515" url="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/m-p/3641515#U3641515"&gt;&lt;/LI-MESSAGE&gt; has sections explaining the IBNS 2.0 commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-663745583" rel="nofollow noopener noreferrer" target="_blank"&gt;Configuring and Understanding the IBNS 2.0 Policy&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1343803953" rel="nofollow noopener noreferrer" target="_blank"&gt;Additional Best-Practice Configurations for IBNS 2.0&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1269031947" rel="nofollow noopener noreferrer" target="_blank"&gt;Differentiated Authentication with IBNS 2.0&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 18:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4590443#M574063</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-11T18:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: C3PL Templet For 802.1X wired</title>
      <link>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4590604#M574074</link>
      <description>&lt;P&gt;Hi Thomas ;&lt;/P&gt;&lt;P&gt;thank you for your response.&lt;/P&gt;&lt;P&gt;that's helped me with my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 01:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/c3pl-templet-for-802-1x-wired/m-p/4590604#M574074</guid>
      <dc:creator>ezzaariyouness</dc:creator>
      <dc:date>2022-04-12T01:59:53Z</dc:date>
    </item>
  </channel>
</rss>

