12-24-2023 02:20 AM
Dears
I would like to use the ISE for the tacacs and guest network and forescout for the rest of the services, can i add both of them in the switches and routers, how things will work in this case the authentication will work with ISE and the dot1x and other features will work with forescout, is this type of setup will work? and how,
The different between ISE and forescout is ISE works before the machine/windows gets the IP address and the forescout works post machine/windows come's up.
Thanks
Solved! Go to Solution.
01-04-2024 01:43 PM
You may configure TACACS+Device Administration AAA servers separate from RADIUS AAA servers in Cisco IOS. "forescout for the rest of the services" is not very specific but it will likely involve making one of your AAA server deployments (ISE or Forescout) a RADIUS proxy for the specific services they are handling.
> The different between ISE and forescout is ISE works before the machine/windows gets the IP address and the forescout works post machine/windows come's up.
That is not 802.1X + RADIUS with ForeScout - that is the SNMP Authentication VLAN method.
12-24-2023 02:33 AM
I would like to use the ISE for the tacacs and guest network
yes this possible based on the configuration you doing for device admin and SSID configuration for Guest you can point to ISE
Other part you mentioned - forescout for the rest of the services, - this was not clear - is this for 802.1x for Wire and Wireless ?
if you using 802.1x for Wired connection then that will be difficult i guess my views.
12-24-2023 03:38 AM
Dear balaji
the rest services are :
Thanks
12-24-2023 05:06 AM
Never tried it with different vendors - look at below example may help you and may meet your requirements :
01-04-2024 01:43 PM
You may configure TACACS+Device Administration AAA servers separate from RADIUS AAA servers in Cisco IOS. "forescout for the rest of the services" is not very specific but it will likely involve making one of your AAA server deployments (ISE or Forescout) a RADIUS proxy for the specific services they are handling.
> The different between ISE and forescout is ISE works before the machine/windows gets the IP address and the forescout works post machine/windows come's up.
That is not 802.1X + RADIUS with ForeScout - that is the SNMP Authentication VLAN method.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide