<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch config for ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700376#M577662</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/832280"&gt;@networker4424&lt;/a&gt; that switch does support 802.1X, you just appear not to have any 802.1X configuration on the interfaces (Gi0/1), so 802.1X will never run.&lt;/P&gt;
&lt;P&gt;To setup wired 802.1X and ISE, refer to &lt;A href="https://integratingit.wordpress.com/2016/12/06/configuring-wired-802-1xmab-authentication-with-cisco-ise/" target="_self"&gt;this guide&lt;/A&gt; to configured wired dot1x or this Cisco guide &lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1018207729" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1018207729&lt;/A&gt; though this guide is more for newer hardware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Oct 2022 07:56:06 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-10-09T07:56:06Z</dc:date>
    <item>
      <title>Switch config for ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700338#M577661</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm trying to configure cisco 3560 for basic 802.1x with ISE 2.6. I have a single PC attached to gigabitEthernet 0/1 but I dont see any pop up on PC to enter username and password. Not sure dot1x is supported on this switch but all the commands are there.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the show output:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;205cisco#show authentication interface gigabitEthernet 0/1&lt;/P&gt;&lt;P&gt;Client list: empty&lt;/P&gt;&lt;P&gt;Available methods list: empty&lt;/P&gt;&lt;P&gt;Runnable methods list: empty&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Version:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;205cisco#show version&lt;BR /&gt;Cisco IOS Software, C3560E Software (C3560E-UNIVERSALK9-M), Version 15.0(2)SE11, RELEASE SOFTWARE (fc3)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank" rel="noopener"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2017 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Sat 19-Aug-17 09:04 by prod_rel_team&lt;/P&gt;&lt;P&gt;ROM: Bootstrap program is C3560E boot loader&lt;BR /&gt;BOOTLDR: C3560E Boot Loader (C3560E-HBOOT-M) Version 12.2(44r)SE5, RELEASE SOFTWARE (fc3)&lt;/P&gt;&lt;P&gt;205cisco uptime is 17 minutes&lt;BR /&gt;System returned to ROM by power-on&lt;BR /&gt;System image file is "flash:c3560e-universalk9-mz.150-2.SE11.bin"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Switch config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;205cisco#show running-config&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 10074 bytes&lt;BR /&gt;!&lt;BR /&gt;version 15.0&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname 205cisco&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;enable password test&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;!&lt;BR /&gt;!!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;ip routing&lt;BR /&gt;no ip dhcp relay information check&lt;BR /&gt;ip dhcp excluded-address 100.100.100.1 100.100.100.200&lt;BR /&gt;ip dhcp excluded-address 192.168.20.32&lt;BR /&gt;ip dhcp excluded-address 192.168.20.1&lt;BR /&gt;ip dhcp excluded-address 192.168.1.1&lt;BR /&gt;ip dhcp excluded-address 192.168.1.2&lt;BR /&gt;ip dhcp excluded-address 20.1.1.1&lt;BR /&gt;ip dhcp excluded-address 10.1.1.1&lt;BR /&gt;ip dhcp excluded-address 30.1.1.1&lt;BR /&gt;ip dhcp excluded-address 40.1.1.1&lt;BR /&gt;ip dhcp excluded-address 50.1.1.1&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool testk&lt;BR /&gt;network 192.168.1.0 255.255.255.0&lt;BR /&gt;lease 0 0 3&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool mike.kou&lt;BR /&gt;network 192.168.20.0 255.255.255.0&lt;BR /&gt;default-router 192.168.20.254&lt;BR /&gt;lease 0 0 1&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool tong&lt;BR /&gt;network 20.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool kevin&lt;BR /&gt;network 192.100.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test1&lt;BR /&gt;network 10.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test2&lt;BR /&gt;network 30.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test3&lt;BR /&gt;network 40.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test4&lt;BR /&gt;network 50.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool test5&lt;BR /&gt;network 60.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test6&lt;BR /&gt;network 70.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test10&lt;BR /&gt;network 100.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool test11&lt;BR /&gt;network 110.1.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp snooping vlan 123&lt;BR /&gt;no ip dhcp snooping information option&lt;BR /&gt;ip dhcp snooping&lt;BR /&gt;ip multicast-routing distributed&lt;BR /&gt;ipv6 icmp error-interval 1&lt;BR /&gt;ipv6 unicast-routing&lt;BR /&gt;ipv6 dhcp pool ipv6-1&lt;BR /&gt;address prefix 10:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-2&lt;/P&gt;&lt;P&gt;address prefix 20:1:1::/64 lifetime 60 30&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-3&lt;BR /&gt;address prefix 30:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-4&lt;BR /&gt;address prefix 40:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-5&lt;BR /&gt;address prefix 50:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-6&lt;BR /&gt;address prefix 60:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-7&lt;BR /&gt;address prefix 70:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-10&lt;BR /&gt;address prefix 100:1:1::/64&lt;BR /&gt;!&lt;BR /&gt;ipv6 dhcp pool ipv6-11&lt;BR /&gt;address prefix 120:1:1::/64&lt;BR /&gt;address prefix 110:1:1::/64&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;vtp domain kk&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-3197563520&lt;BR /&gt;enrollment selfsigned&lt;BR /&gt;subject-name cn=IOS-Self-Signed-Certificate-3197563520&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair TP-self-signed-3197563520&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-3197563520&lt;BR /&gt;certificate self-signed 01&lt;BR /&gt;3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030&lt;BR /&gt;31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;BR /&gt;69666963 6174652D 33313937 35363335 3230301E 170D3131 30333330 30313238&lt;BR /&gt;35395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;BR /&gt;4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 31393735&lt;BR /&gt;36333532 3030819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;BR /&gt;8100EE3B 3962DC20 998C25EB 1C015C98 37024542 18BF3287 9EB685A9 1BDABDB4&lt;BR /&gt;93C534E9 7F84EA0D BB1999FB 9E0A9C55 204617A8 51F28A98 3BEA5D97 8A8D212C&lt;BR /&gt;902EC7C1 A16FF735 8BC504CD 98629F51 3EE48C03 434EF273 E2519E1B 8AAC1A36&lt;/P&gt;&lt;P&gt;quit&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;no spanning-tree vlan 123,400-401,528-600,990,1001,1412,4000&lt;BR /&gt;lacp system-priority 100&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;vlan 10,20,100&lt;BR /&gt;!&lt;BR /&gt;vlan 123&lt;BR /&gt;private-vlan primary&lt;BR /&gt;private-vlan association 1231-1232&lt;BR /&gt;!&lt;BR /&gt;vlan 200-201,300,400&lt;BR /&gt;!&lt;BR /&gt;vlan 500&lt;BR /&gt;private-vlan primary&lt;BR /&gt;private-vlan association 501-502&lt;BR /&gt;!&lt;BR /&gt;vlan 501&lt;BR /&gt;private-vlan isolated&lt;BR /&gt;!&lt;BR /&gt;vlan 502&lt;BR /&gt;private-vlan community&lt;BR /&gt;!&lt;BR /&gt;vlan 600,800,999-1001,1111&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;vlan 1231&lt;BR /&gt;private-vlan isolated&lt;BR /&gt;!&lt;BR /&gt;vlan 1232&lt;BR /&gt;private-vlan community&lt;BR /&gt;!&lt;BR /&gt;vlan 2000-2001,3000,4000&lt;BR /&gt;!&lt;BR /&gt;lldp run&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Loopback0&lt;BR /&gt;ip address 205.205.205.205 255.255.255.255&lt;BR /&gt;ipv6 dhcp relay source-interface Loopback0&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel1&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 2000&lt;BR /&gt;switchport trunk allowed vlan 2000,2001&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel3&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 192.168.3.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel10&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;ip address 10.10.51.205 255.255.255.0&lt;BR /&gt;no ip route-cache&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;switchport access vlan 501&lt;BR /&gt;switchport private-vlan host-association 500 501&lt;BR /&gt;switchport mode private-vlan host&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;switchport access vlan 100&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk allowed vlan 123,1231,1232&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;switchport access vlan 500&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;switchport access vlan 100&lt;BR /&gt;switchport private-vlan host-association 123 1232&lt;BR /&gt;switchport mode private-vlan host&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/6&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk allowed vlan 1,100,200,300&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt;switchport access vlan 100&lt;BR /&gt;switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/8&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 100.100.100.1 255.255.255.0&lt;BR /&gt;ip pim sparse-mode&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/9&lt;BR /&gt;switchport access vlan 1111&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk allowed vlan 1111&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/10&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;ipv6 address 90:1:1::205/64&lt;BR /&gt;ipv6 enable&lt;BR /&gt;ipv6 nd managed-config-flag&lt;BR /&gt;ipv6 dhcp server ipv6-2&lt;BR /&gt;ipv6 ospf 1 area 0&lt;BR /&gt;no cdp enable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/11&lt;BR /&gt;switchport access vlan 4000&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 4000&lt;BR /&gt;switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/12&lt;BR /&gt;switchport access vlan 1000&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/13&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk allowed vlan 1412&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/14&lt;BR /&gt;switchport access vlan 199&lt;BR /&gt;switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/15&lt;/P&gt;&lt;P&gt;switchport access vlan 600&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/16&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/17&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk allowed vlan 200,201,300,400&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/18&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 2000&lt;BR /&gt;switchport trunk allowed vlan 2000,2001&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/19&lt;BR /&gt;switchport access vlan 500&lt;BR /&gt;switchport trunk native vlan 2000&lt;BR /&gt;switchport trunk allowed vlan 2000,2001&lt;BR /&gt;switchport private-vlan mapping 500 501-502&lt;BR /&gt;switchport mode private-vlan promiscuous&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/20&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 2000&lt;BR /&gt;switchport trunk allowed vlan 2000,2001&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/21&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 2000&lt;BR /&gt;switchport trunk allowed vlan 2000,2001&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/22&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/23&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;channel-group 3 mode active&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/24&lt;BR /&gt;no switchport&lt;BR /&gt;no ip address&lt;BR /&gt;channel-group 3 mode active&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/25&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/26&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/27&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/28&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt;no ip address&lt;BR /&gt;ip pim passive&lt;BR /&gt;!&lt;BR /&gt;interface Vlan20&lt;BR /&gt;ip address 22.22.22.2 255.255.255.0&lt;BR /&gt;ipv6 address 2002::2/64&lt;BR /&gt;ipv6 enable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan100&lt;BR /&gt;no ip address&lt;BR /&gt;ip pim passive&lt;BR /&gt;!&lt;BR /&gt;interface Vlan200&lt;BR /&gt;ip address 192.168.2.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan300&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan500&lt;BR /&gt;ip address 50.50.50.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan600&lt;BR /&gt;ip address 192.168.60.46 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan800&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan999&lt;BR /&gt;no ip address&lt;BR /&gt;ipv6 address autoconfig&lt;BR /&gt;ipv6 enable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1000&lt;BR /&gt;ip address 192.168.10.46 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1001&lt;BR /&gt;no ip address&lt;BR /&gt;ipv6 address 2003::1/64&lt;BR /&gt;ipv6 enable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1412&lt;BR /&gt;ip address 148.132.64.194 255.255.255.0&lt;BR /&gt;standby 1 ip 148.132.64.193&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2000&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan4000&lt;/P&gt;&lt;P&gt;ip address 192.168.40.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;router ospf 1&lt;BR /&gt;router-id 2.2.2.2&lt;BR /&gt;network 90.1.1.0 0.0.0.255 area 0&lt;BR /&gt;network 192.168.10.0 0.0.0.255 area 1&lt;BR /&gt;network 192.168.60.0 0.0.0.255 area 0&lt;BR /&gt;!&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip pim rp-address 1.1.1.1&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 10.10.51.1&lt;BR /&gt;ip route 1.1.1.1 255.255.255.255 192.168.2.4&lt;BR /&gt;ip route 3.3.3.3 255.255.255.255 192.168.3.2&lt;BR /&gt;ip route 4.4.4.4 255.255.255.255 192.168.3.2&lt;BR /&gt;ip route 21.1.0.0 255.255.0.0 192.168.3.2&lt;BR /&gt;ip route 21.21.21.0 255.255.255.0 22.22.22.1&lt;BR /&gt;ip route 147.1.0.0 255.255.255.0 205.147.0.147&lt;BR /&gt;ip route 192.168.1.0 255.255.255.0 20.1.1.2&lt;BR /&gt;ip route 192.168.20.0 255.255.255.0 20.1.1.2&lt;BR /&gt;!&lt;BR /&gt;cdp timer 6&lt;BR /&gt;cdp holdtime 12&lt;BR /&gt;arp 10.10.10.1 2222.2222.2211 ARPA&lt;BR /&gt;ipv6 route 130:147::/64 147:205::147&lt;BR /&gt;ipv6 route 2001::/64 2002::1&lt;BR /&gt;ipv6 route 2010:AB8:0:1::/64 147:205::147&lt;BR /&gt;ipv6 router ospf 1&lt;BR /&gt;router-id 2.2.2.2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;radius-server host 10.10.50.65 auth-port 1812 key test&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vstack&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;exec-timeout 0 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;exec-timeout 0 0&lt;BR /&gt;password test&lt;BR /&gt;line vty 5 15&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 01:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700338#M577661</guid>
      <dc:creator>networker4424</dc:creator>
      <dc:date>2022-10-09T01:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700376#M577662</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/832280"&gt;@networker4424&lt;/a&gt; that switch does support 802.1X, you just appear not to have any 802.1X configuration on the interfaces (Gi0/1), so 802.1X will never run.&lt;/P&gt;
&lt;P&gt;To setup wired 802.1X and ISE, refer to &lt;A href="https://integratingit.wordpress.com/2016/12/06/configuring-wired-802-1xmab-authentication-with-cisco-ise/" target="_self"&gt;this guide&lt;/A&gt; to configured wired dot1x or this Cisco guide &lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1018207729" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1018207729&lt;/A&gt; though this guide is more for newer hardware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 07:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700376#M577662</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-10-09T07:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700527#M577667</link>
      <description>&lt;P&gt;Thank you so much Rob, that first one worked out very well, though some commands syntax was a little different but worked pretty well in the end. Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 03:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ise/m-p/4700527#M577667</guid>
      <dc:creator>networker4424</dc:creator>
      <dc:date>2022-10-10T03:08:37Z</dc:date>
    </item>
  </channel>
</rss>

