04-16-2015 08:36 AM - edited 03-10-2019 10:38 PM
Hi Experts ,
We are deploying 802.1x authentication for wired as well as for wireless , I can across one of the terminology where even if radius server is down , clients can get access to network .
I am not sure how it worked by configuring two commands :
authentication event server dead action authorize vlan X
authentication event server alive action reinitialize
statement says that "Use inaccessible authentication bypass to assign the critical port to VLAN "
what is mean by critical port ? and how it works , do we need to configure anything on ISE server ?
is it possible to configure the same for wireless set-up as well ? if yes, what is the configuration we need on wireless lan controllers ?
one more concern about "failed access handling "
if client identity is not valid or credentials are expired what is the recommended option to be configured on ISE for those clients ?
can anybody please share the document which talks about failed access handling in practical set-up.
04-17-2015 03:23 AM
authentication event server dead action authorize vlan X
authentication event server alive action reinitialize
this commands help you to in case if radius server is down then the client connected to this port where this command is given are put in to vlan X (make sure that this vlan is restricted).
And you have following options for client identity not found
If endpoint do not meat any policy's defined then we have a default policy thats applied
04-18-2015 11:34 PM
Thanks Venkatesh ,
you mean, we need one new vlan which will have restricted access ...
how do i configure restricted vlan in my LAN , do i need to create access-list and apply to respective SVI ?
what if I reject the users in case of server failure or have very basic configuration where I do not have any rules configured as inaccessible bypass policy ? what would be impact on network ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide