07-31-2017 05:21 AM
Hi Cisco Communities,
I would like to know your opionion (ISE veterans ) about this implementation that I need to design for an existing ISE installation. (two VM nodes Active/standby ISE version 2.1 patch 1):
REQUIREMENTS :
I would like to know your opinion about these two possibilities :
OPTION A (VLAN Change + DACL) :
OPTION B (SGT reassignment):
Thanks,
M.
Solved! Go to Solution.
08-04-2017 09:50 AM
I'm not an expert, but I'll give an example of what we do here.
With switches, we do DACLs as we have a lot of vlans and would require way to many rules.
Now, we don't allow guests to plug in, but that you could obviously modify for what you need.
So, basically in a closet, the PC and voice have a separate vlan and by default we have an unauth ACL applied to the port.
When the phone logs in, we send down full access DACL and the phone can boot up. When the PC logs in, we send a DACL to give access.
At this point, we only auth the PC from the old system. Going forward we plan to have the PC's send user data so we can send DACLs based off user roles.
Now, we do have a separate vlan for external internet access, so you could send a vlan change down to guests and a DACL to block any access to internal resources.
Anyway, it's very flexible, so really need to look at what is existing and what would be best for the environment.
08-04-2017 09:50 AM
I'm not an expert, but I'll give an example of what we do here.
With switches, we do DACLs as we have a lot of vlans and would require way to many rules.
Now, we don't allow guests to plug in, but that you could obviously modify for what you need.
So, basically in a closet, the PC and voice have a separate vlan and by default we have an unauth ACL applied to the port.
When the phone logs in, we send down full access DACL and the phone can boot up. When the PC logs in, we send a DACL to give access.
At this point, we only auth the PC from the old system. Going forward we plan to have the PC's send user data so we can send DACLs based off user roles.
Now, we do have a separate vlan for external internet access, so you could send a vlan change down to guests and a DACL to block any access to internal resources.
Anyway, it's very flexible, so really need to look at what is existing and what would be best for the environment.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide