cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3601
Views
0
Helpful
3
Replies

ISE and Auto Smartports

gnijs
Level 4
Level 4

I am testing ISE and Auto Smartports and i got the execution of the macro via ISE working.

However, it seems i MUST enable globally "macro auto global processing " before it the macro is really executed.

I would like to avoid this, as enabling this globally, it will automatically run all standard cisco macros for phones, AP, etc.

To prevent this, i need to configure "no macro auto processing" on each and every interface...

Isn't there another way to enable macros but not run the default macros on all ports. Only run -custom- macros when triggered by ISE ?

regards,

Geert

3 Replies 3

Alfonso Lopez
Cisco Employee
Cisco Employee

Would you like to share the document that you followed to get Auto Smarports to work with a response from the ISE?

I can´t find anything where it is well explained.

In the ISE authorization profile, along with "permit" access there are many options. There is one named as "auto-smart-port".

If you write the trigger string in the profile and configure a script with this trigger string on the switch, when the EP interface is authorised with your profile, ISE will send a radius attribute calling the switch to run the script on this EP interface.

It was well documented in Cisco TrustSec solution white papers in my memory. 

-- Best Regards

networkguy13111
Level 1
Level 1

With ISE normally the deployment is switch wide, so to enable it globally can simplify the port configuration.

When dot1x is enabled on an interface, the Cisco auto macro will not run until ISE tells the switch so. It is a bit inconvenient but acceptable.

-- Best Regards