05-06-2019 03:55 AM
Hi,
I was wondering how end-users workstation able to reach ACS. Does it has anything to do with ip helper config in the switches?
802.1X is currently not enable. All policy now control by ISE & ACS. But in the first place, without 802.1x config, how the traffic from all branches can reach AD domain in HQ? Can someone enlighten me?
Solved! Go to Solution.
05-06-2019 06:09 AM
So the IP helper config does not come into play for the 8021x process. The helper will be used to ensure that you can dynamically pull an IP from DHCP. Here is a somewhat brief overview of the 8021x process:
Three main components are used:
1. Supplicant -->port authentication entity seeking network access (workstation)
2. Authenticator-->Network Access Device(switch)
3. Authentication server-->ISE/ACS
EAPoL which is used between your workstation and the switch. Radius is then used between the switch and AAA server. It looks like this:
With that information note that the NAD will manage the communication to your AAA server and the actual workstations will not talk to the AAA server. I hope this clears up the process for you!
05-06-2019 06:09 AM
So the IP helper config does not come into play for the 8021x process. The helper will be used to ensure that you can dynamically pull an IP from DHCP. Here is a somewhat brief overview of the 8021x process:
Three main components are used:
1. Supplicant -->port authentication entity seeking network access (workstation)
2. Authenticator-->Network Access Device(switch)
3. Authentication server-->ISE/ACS
EAPoL which is used between your workstation and the switch. Radius is then used between the switch and AAA server. It looks like this:
With that information note that the NAD will manage the communication to your AAA server and the actual workstations will not talk to the AAA server. I hope this clears up the process for you!
05-06-2019 07:55 AM
i mean currently no 802.1x. How user able to reach ACS (i.e they login everytime PC boots up)? There is no 802.1X now, i wondering how the process like "login to domain" works?
05-06-2019 08:36 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide