<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authenticate endpoints using trusted certificate while ISE is down in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762416#M579407</link>
    <description>&lt;P&gt;I'm looking to see if it's possible for a C9300 to authenticate/authorize endpoints with certificates signed by a trusted CA while ISE is down. Below is my current policy-map for ISE being down&lt;/P&gt;&lt;P&gt;event authentication-failure match-first&lt;BR /&gt;10 class ISE_SVR_DOWN_AUTHD_HOST do-until-failure&lt;BR /&gt;10 pause reauthentication&lt;BR /&gt;20 authorize&lt;BR /&gt;20 class ISE_SVR_DOWN_UNAUTHD_HOST do-until-failure&lt;BR /&gt;10 activate service-template Internet-Only-Template&lt;/P&gt;&lt;P&gt;class ISE_SVR_DOWN_AUTHD_HOST is matching "result-type aaa timeout" and "authorization-status authorized" to maintain the current authorization status of an endpoint, whether it's a workstation, VoIP, wired IoT, etc.&lt;/P&gt;&lt;P&gt;class ISE_SVR_DOWN_UNAUTHD_HOST is matching "result-type aaa timeout" and "authorization-status unauthorized" which will activate a template that denies traffic to private IPs (excluding DHCP) and allows internet-traffic for wired guests.&lt;/P&gt;&lt;P&gt;This has worked well so far, but a power-failure event on the switch will eliminate the authorized status of endpoints. If this happens, corporate endpoints are only able to reach the internet. I'm trying to avoid re-initiated VLANs as there's no telling if a guest or corporate endpoint is connected on the switch interface.&lt;/P&gt;&lt;P&gt;Is there a way to have the 9300 check for certificates and authorize devices based on certificates signed by a trusted CA?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 20:49:06 GMT</pubDate>
    <dc:creator>Kacker</dc:creator>
    <dc:date>2023-01-25T20:49:06Z</dc:date>
    <item>
      <title>Authenticate endpoints using trusted certificate while ISE is down</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762416#M579407</link>
      <description>&lt;P&gt;I'm looking to see if it's possible for a C9300 to authenticate/authorize endpoints with certificates signed by a trusted CA while ISE is down. Below is my current policy-map for ISE being down&lt;/P&gt;&lt;P&gt;event authentication-failure match-first&lt;BR /&gt;10 class ISE_SVR_DOWN_AUTHD_HOST do-until-failure&lt;BR /&gt;10 pause reauthentication&lt;BR /&gt;20 authorize&lt;BR /&gt;20 class ISE_SVR_DOWN_UNAUTHD_HOST do-until-failure&lt;BR /&gt;10 activate service-template Internet-Only-Template&lt;/P&gt;&lt;P&gt;class ISE_SVR_DOWN_AUTHD_HOST is matching "result-type aaa timeout" and "authorization-status authorized" to maintain the current authorization status of an endpoint, whether it's a workstation, VoIP, wired IoT, etc.&lt;/P&gt;&lt;P&gt;class ISE_SVR_DOWN_UNAUTHD_HOST is matching "result-type aaa timeout" and "authorization-status unauthorized" which will activate a template that denies traffic to private IPs (excluding DHCP) and allows internet-traffic for wired guests.&lt;/P&gt;&lt;P&gt;This has worked well so far, but a power-failure event on the switch will eliminate the authorized status of endpoints. If this happens, corporate endpoints are only able to reach the internet. I'm trying to avoid re-initiated VLANs as there's no telling if a guest or corporate endpoint is connected on the switch interface.&lt;/P&gt;&lt;P&gt;Is there a way to have the 9300 check for certificates and authorize devices based on certificates signed by a trusted CA?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 20:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762416#M579407</guid>
      <dc:creator>Kacker</dc:creator>
      <dc:date>2023-01-25T20:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate endpoints using trusted certificate while ISE is down</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762432#M579408</link>
      <description>&lt;P&gt;No, the switch does not terminate EAP.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 21:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762432#M579408</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-01-25T21:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate endpoints using trusted certificate while ISE is down</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762443#M579409</link>
      <description>&lt;P&gt;Thank you for your response. Knowing this, do you have an recommendations for allowing access to corporate VLANs during an ISE outage without allowing unintended guests access to the same VLAN?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 21:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762443#M579409</guid>
      <dc:creator>Kacker</dc:creator>
      <dc:date>2023-01-25T21:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate endpoints using trusted certificate while ISE is down</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762450#M579411</link>
      <description>&lt;P&gt;A couple of options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Apply an ACL that is a balance of necessary corporate access while not being totally open to potential guest endpoints&lt;/LI&gt;
&lt;LI&gt;Statically configure VLANs/Access for guest endpoints (don't rely on ISE to assign if this endpoint is guest or not).&lt;/LI&gt;
&lt;LI&gt;Accept this as a security risk if ISE is down.&amp;nbsp; Have proper HA/distributed deployment to handle any ISE outages.&amp;nbsp; Also a robust WAN with proper failover to mitigate.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 25 Jan 2023 22:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762450#M579411</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-01-25T22:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate endpoints using trusted certificate while ISE is down</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762452#M579412</link>
      <description>&lt;P&gt;I appreciate the helpful tips. It seems this will be an accepted risk considering the scenario. Thank you for the feedback!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 22:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-endpoints-using-trusted-certificate-while-ise-is/m-p/4762452#M579412</guid>
      <dc:creator>Kacker</dc:creator>
      <dc:date>2023-01-25T22:26:12Z</dc:date>
    </item>
  </channel>
</rss>

