cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
421
Views
0
Helpful
1
Replies

CWA -Differentiate between domain and stanalone assets.

sudheere
Level 1
Level 1

I am implementing ISE (1.1.1) for an larg   organization. I am using IEEE802.1x   computer auth for Domain joined computers and  CWA for Non-domain computers(AD/domain user and guest user).  Posture policy is defferent for domain and non-domain computers. I want to make CWA as fallback method for domain computers. Which attribute/condition can I use to defferntiate a domain and non-domain asset/computer if the user login with CWA.

1 Reply 1

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

You can leverage the MachineAccessRestriction feature. Look for the condition or attribute "was machine authenticated" that should let you know that a domain asset authenticated to the network. Also you can use anyconnect NAM or a group policy to set the domain issued workstations to use computer and user authentication.

Thanks,

Tarik Admani
*Please rate helpful posts*