cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
670
Views
0
Helpful
3
Replies

2 ISE radius groups CISCO Switches

Richard Lucht
Level 1
Level 1

We currently have a pair of ISE for network device access and authenticating VPN and Wireless.  Now this is for about 14000 users.  We plan on setting up a larger ISE deployment to use for authentication on the VPN and wireless as well as wired 802.1x and MAB.  I am looking for some help on setting up the aaa authentication servers

 

Now I have an ISE setup in the lab and I want to call it aaa group server radius B.  I want B to be the one to authenticate VPN, wireless and the wired.  Am I missing something the AAA settings and which setting would I use B?

 

 

aaa group server radius A
server name ISE3

 

 

aaa authentication login default group A local-case
aaa authentication dot1x default group A
aaa authorization console
aaa authorization exec default group A local
aaa authorization network default group A

3 Replies 3

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Based on your output you'll need to create a new radius group and modify the aaa network and dot1x. However for doing wired dot1x, you'll need other configs. Do you need help on the other configs?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

A pdf from Cisco that explain all commands for dot1x


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thank you, I will take a look at it tomorrow morning.