10-12-2022 10:43 PM
Hi Experts,
we know that Cisco ISE is a security policy management platform that provides secure access to network resources, can we do bandwidth control by Cisco ISE policy for Wired clients (802.1x Clients) on a per user or gruop basis?
Solved! Go to Solution.
10-13-2022 05:17 AM
Thanks, I am looking for the QoS configuration example or solution for the Cisco Catalyst 9300 Series Switches and ISE Authorization profile idea. I did applied worksome but not as expected output gotten. I used AuthZ profile for Cisco:cisco-data-rate Radius advance attributies.
10-26-2022 05:43 AM
I am getting some idea from below materials but still working on it.
https://www.wiresandwi.fi/blog/solid-config-cisco-ibns-2-0-802-1x-mab-switch-configuration-ios-xe
10-13-2022 12:09 AM
may be you need to manually configure on the switches?
10-13-2022 01:53 AM
Thanks a lot for your comment but I think there should be way bind policy with Switch like Cisco WLC. If you have any idea
10-13-2022 02:54 AM
Wiress is different compare to Wired network.
You can use QoS policies as suggested.
10-13-2022 02:57 AM
@Ferdaush You can authorise the users by AD user or group membership and then dynamically send the specific RADIUS attributes. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_radatt/configuration/15-mt/sec-usr-radatt-15-mt-book/sec-rad-att-AAA-per-VC.html
10-13-2022 03:05 AM
Just to clarity is this works on Ethernet port ? (never tested) - but keen to know.
10-13-2022 04:15 AM
Yes, Ethernet port.
10-13-2022 04:21 AM
I idea is use Cisco ISE instead of Packetshaper system in some cases. May be control network bandwidth by user or AD group basis. Thanks @balaji.bandi and @Rob Ingram for your response.
10-13-2022 04:25 AM
@Ferdaush another option you could apply the QoS configuration (and other settings) in an interface template. Then from ISE use the authorisation profile to define the interface template and assign this on a per AD group basis.
10-13-2022 05:17 AM
Thanks, I am looking for the QoS configuration example or solution for the Cisco Catalyst 9300 Series Switches and ISE Authorization profile idea. I did applied worksome but not as expected output gotten. I used AuthZ profile for Cisco:cisco-data-rate Radius advance attributies.
10-16-2022 02:30 AM
Could you please share "QoS configuration (and other settings) in an interface template" if you have any @Rob Ingram
10-26-2022 05:43 AM
I am getting some idea from below materials but still working on it.
https://www.wiresandwi.fi/blog/solid-config-cisco-ibns-2-0-802-1x-mab-switch-configuration-ios-xe
10-26-2022 05:54 AM
One More document found as below link:
https://community.cisco.com/t5/security-knowledge-base/neat-with-interface-template/ta-p/3642967
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide