<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and switch connected to floorbox socket in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322070#M1122313</link>
    <description>&lt;P&gt;Sorry continue with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Let him help you to config ISE to authc SW connect to other SW&lt;/P&gt;
&lt;P&gt;Goodluck&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2025 18:18:50 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-08-19T18:18:50Z</dc:date>
    <item>
      <title>ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321870#M1122294</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have following situation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ISE 3.4 Patch 3&lt;/LI&gt;
&lt;LI&gt;Access switch for floor boxes sockets WS-C2960X-48LPS-L with&amp;nbsp;15.2(7)E10&lt;/LI&gt;
&lt;LI&gt;2 Access switches for lab IP phones (96 phones)&amp;nbsp;WS-C3560X-48P with&amp;nbsp;15.2(4)E3 - connected to public floor box socket and there is TRUNK with 2 allowed VLANs between these switches and switches cabled to floor box sockets (line above) and these switches have 1 SVI for management (as there is not enough floor box sockets to use management port)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I know this is not the best how to do it, but this lab must be public accessible and there is no other way how to connect 96 phones and their switches to core switches in server room physically securely. I also know switches are EOS, just ignore it, they are working.&lt;/P&gt;
&lt;P&gt;The thing is that I we are security all floor box sockets with ISE. The problem I have is that IP hones switches have old IOS and does not support TLS1.2 for dot1x. So only way how to use EAP supplicant is to allow TLS1.0 on ISE. If I use MAB, then all IP phones are authenticated twice - first on their access switch in lab, second on parent access switch in server room (where all floor boxes sockets are cabled).&lt;/P&gt;
&lt;P&gt;I do not know how to do it secure with current equipment. If keep only MAB on that floor box sockets in lab and disable dot1x EAP, or rather allow TLS1.0 on ISE and use dot1x EAP-FAST on IP phones switch and disable MAB on floor box switch. I was also looking into policies sets, that I do not know how to create condition for policy set as "Normalised Radius·RadiusFlowType == Wired802_1x &amp;amp;&amp;amp; TLSVersion == TLSv1" - there is nothing like TLSVersion in possible options and do not know how to use it, even in Live Log is visible in Other Attributes.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 08:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321870#M1122294</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2025-08-19T08:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321875#M1122295</link>
      <description>&lt;P&gt;Sorry I dont get your request&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SW to SW you can use MACSec&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phone to network you can use 802.1x and/or mab&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 08:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321875#M1122295</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T08:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321884#M1122296</link>
      <description>&lt;P&gt;Let me clarify it. I want to know opinions how to secure Access Switch in server room, which is physically cabled to floor box sockets. So if anybody come to that LAB room and disconnect access switch (used for IP phones) from floor box sockets, so floor box socket will be stills secured by ISE and nobody unauthorized can use it.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 08:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321884#M1122296</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2025-08-19T08:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321890#M1122297</link>
      <description>&lt;P&gt;MAB or 802.1x use only in SW direct connect to endpoint&lt;/P&gt;
&lt;P&gt;I.e. this need to use in cat3500 series&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 09:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321890#M1122297</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T09:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321894#M1122298</link>
      <description>&lt;P&gt;You need Access SW run as supplicant?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 09:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321894#M1122298</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T09:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321904#M1122299</link>
      <description>&lt;P&gt;This sounds like a use case for NEAT (Network Edge Authentication Technology). Have a look at this reference to see if it addresses your requirement and concerns:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-286005059" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-286005059&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 09:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321904#M1122299</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-08-19T09:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321910#M1122301</link>
      <description>&lt;P&gt;It looks like the ISE and switch are connected to the floorbox sockets, please check the wiring and ensure the configuration is correct.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 10:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321910#M1122301</guid>
      <dc:creator>bonniefr</dc:creator>
      <dc:date>2025-08-19T10:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321964#M1122303</link>
      <description>&lt;P&gt;hope this screenshot help to understand what I'm trying to solve. I do not know if there is other way than using MAB only multi-auth on that socket (where each phone is authenticated twice - switches in lab and then in server room due MAB and multi-auth), or rather allow TLSv1.0 on ISE and configure switches in phone lab as supplicant (they are old, no TLSv1.2 on them).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schema.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250508iECD7AE9015E95EDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="schema.png" alt="schema.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 13:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321964#M1122303</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2025-08-19T13:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321981#M1122308</link>
      <description>&lt;P&gt;You need to authc endpoints connect to access SW ?&lt;/P&gt;
&lt;P&gt;If access SW have UP mgmt interface can connect to ISE then access SW can authc the endpoints' and after these endpoints authc it can access network' i.e. checkpoint need close to endpoint and after this checkpoint ypu can go wherever you want.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 13:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5321981#M1122308</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T13:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322019#M1122310</link>
      <description>&lt;P&gt;Did you look at the link I shared regarding NEAT setup? With that, the access switch in the server room authenticates the switch connected to the floor box socket. That switch in turn is the network access device passing requests to ISE to authenticate the IP phones (with MAB). If anything else is plugged directly into a floor box socket, it authenticates via the server room switch. No TLS 1.0 is used and the phones should only ever appear in authentication sessions of the switch they are directly plugged into.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 15:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322019#M1122310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-08-19T15:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322069#M1122312</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;yes, looks it is what I need. I have to study it more, I'm still beginner with ISE.&lt;/P&gt;
&lt;P&gt;Also you are all more experienced, so can anybody tell me where to look for if I want to make Policy condition based on any attribute from live log "Other attributes" section on ISE 3.4?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 18:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322069#M1122312</guid>
      <dc:creator>Tibor M</dc:creator>
      <dc:date>2025-08-19T18:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and switch connected to floorbox socket</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322070#M1122313</link>
      <description>&lt;P&gt;Sorry continue with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Let him help you to config ISE to authc SW connect to other SW&lt;/P&gt;
&lt;P&gt;Goodluck&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 18:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-switch-connected-to-floorbox-socket/m-p/5322070#M1122313</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T18:18:50Z</dc:date>
    </item>
  </channel>
</rss>

