12-22-2017 10:32 AM
Hi experts,
I have a customer that wants to understand if we can authentication a user using both 802.1X AND Mac address authentication at the same time, i.e., not only make sure the user/pass is correct but that the MAC address of his device should be granted access.
Does the 802.1X RADIUS Message to ISE also include the MAC Address of the device so that we can also use that MAC Address as an additional layer of compliance to grant access?
Thanks in advance,
José
Solved! Go to Solution.
12-22-2017 10:38 AM
Yes you would setup an authorization policy with a basic rule
If AllowedEndpoints and dot1x then permit access
12-22-2017 10:38 AM
Yes you would setup an authorization policy with a basic rule
If AllowedEndpoints and dot1x then permit access
12-22-2017 10:44 AM
To clarify and expand on comments to internal post, there is only one authentication (802.1X) in this scenario. As Jason noted, you can also validate the Calling-Station-Id (MAC address of LAN user) to an allowed list such as Endpoint Identity Group with specific permissions.
12-22-2017 10:46 AM
Great, thank you both for your quick replies!
12-22-2017 01:14 PM
This is assuming you have a system (import or API) to add endpoints and assign them to identity groups in place.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide