cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
0
Helpful
7
Replies

Cisco ISE 802.1x with PassiveID

peter.matuska1
Level 1
Level 1

Hi,

we have EAP-FAST (machine and user authentication) working. Can we enable passiveid on this ISE to get more information from AD? Is it supported configuration? Won't it cause any trouble since ISE will see the same record for a user from 802.1x and passiveid?

thank you

1 Accepted Solution

Accepted Solutions

Yeah I would really push back on that decision.  

View solution in original post

7 Replies 7

Why would you want to do this?  Passive ID is way less accurate than active authentication which you already have with EAP-FAST.

peter.matuska1
Level 1
Level 1

some devices may not have anyconnect installed so at least something.

What type of devices do y have AnyConnect installed that would still be authenticating against AD? What extra visibility are you looking for by scraping AD login events?

peter.matuska1
Level 1
Level 1

Customer wants to do the FW rules for servers where anyconnect cannot be installed. So the passiveid is enabled for them.

Why do you need ISE/Passive ID for server firewall rules? Don’t they have static IPs? Who is logging into the servers to even generate a AD login event? What about non-Windows servers?

not sure, not my decision

Yeah I would really push back on that decision.