11-04-2021 09:34 PM
What are the suggested configuration for WLC and Catalyst Switches if ISE authentication fails in a single server environment? What other DB users sources could be used? The endpoints could gain acces to the network? Under what conditions/configurations? If posture features will be used and ISE is unavailable, what will be the behaviour?
Thanks a lot for your responses!
Solved! Go to Solution.
11-05-2021 04:59 AM
Totally agree with @Kasun Bandara comments.
The endpoints could gain acces to the network? Under what conditions/configurations? If posture features will be used and ISE is unavailable, what will be the behaviour?
-There are some other mechanisms you can configure/deploy on your NADs. For example, role based critical authz. This essentially grants clients the same network access even when ISE is not reachable next time in the event of an outage. Take a look here at further info: ISE Secure Wired Access Prescriptive Deployment Guide - Cisco Community
HTH!
11-04-2021 09:39 PM
Hi,
if ISE is unavailable, already authenticated users will keep sessions till timeout and new authentications/posture tests/etc, will fail to continue.
rate this and mark as answer, if this resolved your issue
11-05-2021 04:59 AM
Totally agree with @Kasun Bandara comments.
The endpoints could gain acces to the network? Under what conditions/configurations? If posture features will be used and ISE is unavailable, what will be the behaviour?
-There are some other mechanisms you can configure/deploy on your NADs. For example, role based critical authz. This essentially grants clients the same network access even when ISE is not reachable next time in the event of an outage. Take a look here at further info: ISE Secure Wired Access Prescriptive Deployment Guide - Cisco Community
HTH!
11-23-2021 10:56 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide