cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1774
Views
0
Helpful
2
Replies

How to push an authorization profile from ISE to a 9800 WLC

etarnow
Level 1
Level 1

I am trying to create an authorization profile on ISE for machine authentication when using PEAP. (We are moving away from this but it has to be supported for now.) If a machine has never authenticated on wireless before, it should receive restricted access to only talk to AD to authenticate. I have been unable to figure out how to do this with ISE and a 9800 WLC (under version 17.10.x, I cannot use dACLs). Previously this was done by the Airspace ACL Name task but this doesn't seem to be supported by the 9800 controllers.

Is the way to go with web authentication? That seems geared more for guest access and not for this application.

Any help would be appreciated, thank you.

2 Accepted Solutions

Accepted Solutions

Arne Bier
VIP
VIP

Hello

Think of the 9800 like you would any Catalyst switch - you would use dACLs to achieve this.

Have a look at this link about dACLs on 9800.

In ISE, you would create the dACL, give it a name, and then in the ISE Authorization Profile, you can select that dACL from a drop down list.

View solution in original post

2 Replies 2