<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Andre-I am afraid you don't in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659392#M74547</link>
    <description>&lt;P&gt;Andre-&lt;/P&gt;&lt;P&gt;I am afraid you don't have many options here. I have faced this problem before during my deployments. The problem is that ISE is needed in order to signal the switch to remove the pre-auth ACL by applying a dACL. However, since ISE is not available, the switch can authorize the endpoints to a VLAN but no you need another method to remove the pre-auth ACL. In the past I have accomplished this via one of the following:&lt;/P&gt;&lt;P&gt;1. EEM script that re-configures the switch and sets the pre-auth ACL to "permit ip any any" (or remove the pre-auth ACL all together)&amp;nbsp;when/if the ISE servers become unavailable. I thought this feature required IP Services but looking at the following doc it looks like you could do it with IP Base too. I guess you can give it a try and see what happens &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-special-early-deployments/product_bulletin_c25-614546.html"&gt;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-special-early-deployments/product_bulletin_c25-614546.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;eem script example:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf"&gt;http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. The second method requires a converged access switch (3850, 3650). Those switches can be configured with profiles where the pre-auth ACL can be replaced with a critical ACL in the event of an ISE outage.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Feb 2015 02:31:27 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2015-02-19T02:31:27Z</dc:date>
    <item>
      <title>Access with ISE server dead</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659387#M74538</link>
      <description>&lt;P&gt;Hello there,&lt;BR /&gt;I´d like to know how to give access for users when ISE is dead.&lt;BR /&gt;I´m asking that because I´m using pre authentication ACL, so even with the command authentication event server dead action authorize vlan XX the access will be limited, will not it?&lt;/P&gt;&lt;P&gt;My pre authentication&amp;nbsp;acl allow access only to ISE, DNS and DHCP requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659387#M74538</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2019-03-11T05:26:47Z</dc:date>
    </item>
    <item>
      <title>Hi Andre-Can you tell me:-</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659388#M74540</link>
      <description>&lt;P&gt;Hi Andre-&lt;/P&gt;&lt;P&gt;Can you tell me:&lt;/P&gt;&lt;P&gt;- Model of switches used&lt;/P&gt;&lt;P&gt;- Version of code running&lt;/P&gt;&lt;P&gt;- Image running (IP Base, IP Services, etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 01:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659388#M74540</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-14T01:07:35Z</dc:date>
    </item>
    <item>
      <title>You could use a preauth ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659389#M74542</link>
      <description>&lt;P&gt;You could use a preauth ACL of 'permit ip any any'.&amp;nbsp;As long as ISE is functioning it can assign a&amp;nbsp;tailored dynamic ACL&amp;nbsp;for both a 802.1X-enabled endpoint and another&amp;nbsp;(more restrictive) ACL&amp;nbsp;for nonresponsive (MAB) endpoint according to the authorization rules. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the ISE fails, the &lt;STRONG&gt;authentication event server dead action authorize vlan&lt;/STRONG&gt;&amp;nbsp;command places the port into a suitable critical VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 16:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659389#M74542</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2015-02-15T16:58:28Z</dc:date>
    </item>
    <item>
      <title>Hi Peter,my pre</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659390#M74543</link>
      <description>&lt;P&gt;Hi Peter,&lt;/P&gt;&lt;P&gt;my pre authentication ACL only allow access to ISE, DNS and DHCP requests.&lt;/P&gt;&lt;P&gt;If the ISE fails and I put the users on a critical VLAN the ACL will still limiting the access, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 22:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659390#M74543</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-02-18T22:55:23Z</dc:date>
    </item>
    <item>
      <title>Hello Neno,- Model of</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659391#M74546</link>
      <description>&lt;P&gt;Hello Neno,&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;- Model of switches used: 2960&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;- Version of code running: 12.2(55)SE3&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;- Image running (IP Base, IP Services, etc): IP Base.&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 23:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659391#M74546</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-02-18T23:18:10Z</dc:date>
    </item>
    <item>
      <title>Andre-I am afraid you don't</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659392#M74547</link>
      <description>&lt;P&gt;Andre-&lt;/P&gt;&lt;P&gt;I am afraid you don't have many options here. I have faced this problem before during my deployments. The problem is that ISE is needed in order to signal the switch to remove the pre-auth ACL by applying a dACL. However, since ISE is not available, the switch can authorize the endpoints to a VLAN but no you need another method to remove the pre-auth ACL. In the past I have accomplished this via one of the following:&lt;/P&gt;&lt;P&gt;1. EEM script that re-configures the switch and sets the pre-auth ACL to "permit ip any any" (or remove the pre-auth ACL all together)&amp;nbsp;when/if the ISE servers become unavailable. I thought this feature required IP Services but looking at the following doc it looks like you could do it with IP Base too. I guess you can give it a try and see what happens &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-special-early-deployments/product_bulletin_c25-614546.html"&gt;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-software-releases-12-2-special-early-deployments/product_bulletin_c25-614546.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;eem script example:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf"&gt;http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. The second method requires a converged access switch (3850, 3650). Those switches can be configured with profiles where the pre-auth ACL can be replaced with a critical ACL in the event of an ISE outage.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2015 02:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659392#M74547</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-19T02:31:27Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno,I´ll try an EEM.</title>
      <link>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659393#M74548</link>
      <description>&lt;P&gt;Thanks Neno,&lt;/P&gt;&lt;P&gt;I´ll try an EEM.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2015 15:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-with-ise-server-dead/m-p/2659393#M74548</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-02-19T15:18:38Z</dc:date>
    </item>
  </channel>
</rss>

