03-14-2024 05:26 AM
Hi experts,
I'm new into ISE and wonder if there is a way to only accept connections from wireless devices using 802.1x-PEAP by using UPN (email address) and not the ones using SAM (pre-Windows 2000 logon).
Regards.
Solved! Go to Solution.
03-14-2024 03:08 PM
My first thought would be to simply create an authentication policy that matches on the UPN suffix. If the session does not match that, it will hit the Default authC policy, which would be set for DenyAccess.
03-14-2024 03:08 PM
My first thought would be to simply create an authentication policy that matches on the UPN suffix. If the session does not match that, it will hit the Default authC policy, which would be set for DenyAccess.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide