<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1X(AD) + MAC Filtering via ISE in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514228#M305611</link>
    <description>&lt;P&gt;I currently am only doing 802.1X(AD) on the SSID.  My users have figured out they can get their personal iPhone on the SSID by entering their AD credentials.  I would like to do 802.1X(AD) + MAC Filtering via ISE.  This way the device would have to be in the MAC allowed group plus their AD credentials.  Does anyone how I can accomplish this?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Feb 2024 20:12:08 GMT</pubDate>
    <dc:creator>rlwilson</dc:creator>
    <dc:date>2024-02-20T20:12:08Z</dc:date>
    <item>
      <title>802.1X(AD) + MAC Filtering via ISE</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514228#M305611</link>
      <description>&lt;P&gt;I currently am only doing 802.1X(AD) on the SSID.  My users have figured out they can get their personal iPhone on the SSID by entering their AD credentials.  I would like to do 802.1X(AD) + MAC Filtering via ISE.  This way the device would have to be in the MAC allowed group plus their AD credentials.  Does anyone how I can accomplish this?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 20:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514228#M305611</guid>
      <dc:creator>rlwilson</dc:creator>
      <dc:date>2024-02-20T20:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X(AD) + MAC Filtering via ISE</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514229#M305612</link>
      <description>&lt;P&gt;This is nothing more than an additional condition in the corresponding rule in the authorization policy. But it is also an administrative nightmare.&lt;/P&gt;&lt;P&gt;The better solution would be to use TEAP with EAP-Chaining.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 21:29:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514229#M305612</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-02-20T21:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X(AD) + MAC Filtering via ISE</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514230#M305613</link>
      <description>&lt;P&gt;There is all the information that you need.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Cisco_ISE_-_MR_Access_Points" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Cisco_ISE_-_MR_Access_Points&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 21:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514230#M305613</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2024-02-20T21:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X(AD) + MAC Filtering via ISE</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514231#M305614</link>
      <description>&lt;P&gt;If you have deployed Meraki Systems Manager on your corporate wireless assets, but not the employees personal devices, you can also filter on whether the Systems Manager agent is on the wireless device too.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 22:14:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514231#M305614</guid>
      <dc:creator>jgbright</dc:creator>
      <dc:date>2024-02-20T22:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X(AD) + MAC Filtering via ISE</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514232#M305615</link>
      <description>&lt;P&gt;Another better solution is to give them internet access on a dedicated SSID (for example, the Guest SSID) for their personal devices.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 10:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-ad-mac-filtering-via-ise/m-p/5514232#M305615</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-02-21T10:56:08Z</dc:date>
    </item>
  </channel>
</rss>

