01-16-2018 11:22 PM
Hi, In our current deployment we allow endpoint to get IP address then it will authenticate.
is it possible we first allow the device to authenticate then after successful auth they will
get IP.
Any one test this scenario?
Solved! Go to Solution.
01-17-2018 09:29 AM
It depends on auth type. Using 802.1X, it is certainly possible to authenticate via L2 protocol and then allow access to DHCP after successful authentication. This is definitely the case in closed mode where endpoint has no access until auth successful.
For MAB, it is also possible to first authenticate/authorize MAC address prior to IP address assignment. Of course, it is not possible to perform web authentication until IP address received. This is why a typical CWA policy will allow DHCP and set redirect as the result of MAC auth.
RADIUS Accounting Interim Update with notify ISE if IP address received after initial authentication and Accounting Start sent.
01-17-2018 09:29 AM
It depends on auth type. Using 802.1X, it is certainly possible to authenticate via L2 protocol and then allow access to DHCP after successful authentication. This is definitely the case in closed mode where endpoint has no access until auth successful.
For MAB, it is also possible to first authenticate/authorize MAC address prior to IP address assignment. Of course, it is not possible to perform web authentication until IP address received. This is why a typical CWA policy will allow DHCP and set redirect as the result of MAC auth.
RADIUS Accounting Interim Update with notify ISE if IP address received after initial authentication and Accounting Start sent.
01-17-2018 06:10 PM
Hi chyps,
Do you have link or manual I can refer to apply the information you said?
01-17-2018 10:41 PM
See How To: ISE Phased Deployments and How To: Deploy ISE in Closed Mode
and Cisco Live BRKSEC-2691
For Wireless, it requires auth first before DHCP, unless the WLAN setup in open mode.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide