<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco NAC and MACSEC Switch connection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5282145#M595993</link>
    <description>&lt;P&gt;Hi Rob&lt;/P&gt;&lt;P&gt;Thanks for the confirming what I thought also. Yeah I cannot see why it would not work., Noted also on not enabling NAC on any of the&amp;nbsp; switch to switch connections be it they use macsec or not .&amp;nbsp;&lt;/P&gt;&lt;P&gt;So our connection would be something along these lines&lt;/P&gt;&lt;P&gt;Site 1 FD switch &lt;EM&gt;&amp;lt;Fiber with macseclink&amp;gt;&amp;nbsp;&lt;/EM&gt; Site 2 switch A &lt;EM&gt;&amp;lt;Fiber link&amp;gt;&lt;/EM&gt; Site 2 Switch B .&lt;/P&gt;&lt;P&gt;Site 2 switches access ports only enabled with NAC&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2025 02:32:52 GMT</pubDate>
    <dc:creator>Davis-Revent-12</dc:creator>
    <dc:date>2025-04-17T02:32:52Z</dc:date>
    <item>
      <title>Cisco NAC and MACSEC Switch connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281916#M595978</link>
      <description>&lt;DIV&gt;Hi Cisco NAC peeps&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We have an existing deployment using Cisco NAC configured on cat ios-xe switches i.e. 9400 that have NAC enabled access interfaces for authentication via Cisco ISE using 802.1x cert auth for PCs and mab authentication for other devices.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;My questions are&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;1) If we connect a new access layer switch from a new site - call it site 2 across the road using fiber to the existing site 1 FD switch will NAC still work on it still if we connect at layer 2 and enable psk mac sec between the switch's trunk links connecting site 1 to site 2 which is network-link mode and with the access ports on the new site 2 switch enabled with NAC on the access interfaces also ?&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;2) Can we also connect off the new site 2 switch another switch off it i.e. daisy chain on layer 2 and run nac .&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;so, it would be connected as: site 1 switch FD &amp;lt;&amp;gt; site 2 switch A &amp;lt;&amp;gt; site 2 switch B.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I am fairly sure it will still work with NAC etc. but just seeing if anything would be an issue - Apart from the obvious potential bottleneck on the first switch 2 uplinks to switch 1 FD switch&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Any comments would be welcome&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281916#M595978</guid>
      <dc:creator>Davis-Revent-12</dc:creator>
      <dc:date>2025-04-16T12:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC and MACSEC Switch connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281957#M595981</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1867368"&gt;@Davis-Revent-12&lt;/a&gt; I don't foresee a problem with this, MACsec will be enabled on the interfaces connecting the switches and NAC (802.1X/MAB) enabled on the switchports the endpoints are connected too. The switches will need a mgmt IP address to be able to communicate with ISE using RADIUS and configured for NAC.&lt;/P&gt;
&lt;P&gt;Yes you can daisy chain another switch, just don't enable NAC on the interfaces between switches.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 13:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281957#M595981</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-04-16T13:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC and MACSEC Switch connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281968#M595985</link>
      <description>&lt;P&gt;Should be no issue.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 13:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5281968#M595985</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-04-16T13:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC and MACSEC Switch connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5282145#M595993</link>
      <description>&lt;P&gt;Hi Rob&lt;/P&gt;&lt;P&gt;Thanks for the confirming what I thought also. Yeah I cannot see why it would not work., Noted also on not enabling NAC on any of the&amp;nbsp; switch to switch connections be it they use macsec or not .&amp;nbsp;&lt;/P&gt;&lt;P&gt;So our connection would be something along these lines&lt;/P&gt;&lt;P&gt;Site 1 FD switch &lt;EM&gt;&amp;lt;Fiber with macseclink&amp;gt;&amp;nbsp;&lt;/EM&gt; Site 2 switch A &lt;EM&gt;&amp;lt;Fiber link&amp;gt;&lt;/EM&gt; Site 2 Switch B .&lt;/P&gt;&lt;P&gt;Site 2 switches access ports only enabled with NAC&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 02:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5282145#M595993</guid>
      <dc:creator>Davis-Revent-12</dc:creator>
      <dc:date>2025-04-17T02:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC and MACSEC Switch connection</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5282150#M595994</link>
      <description>&lt;P&gt;Thanks for responding&amp;nbsp; back also and confirming as such&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 02:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-and-macsec-switch-connection/m-p/5282150#M595994</guid>
      <dc:creator>Davis-Revent-12</dc:creator>
      <dc:date>2025-04-17T02:24:44Z</dc:date>
    </item>
  </channel>
</rss>

