Showing results for 
Search instead for 
Did you mean: 

ISE and no External Identity Source


I have this particular case in which I need to make authentications for users in ISE without Active Directory/LDAP etc.


I would like to have some kind of MAC to USER binding where the user would no be able to add more devices to the network. I know the eap chaining using anyconnect is a way of achieving this but then again I can only see it using AD or some kind of external database. Also printers, wireless and phones are in the map. I tried using MAB and CWA for this but do not want to have the users be able to self register their devices as if they were guests.


EAP chaining without AD??? Possible?

Any hope?

Thank you 

3 Replies 3

Cisco Employee
Cisco Employee

Someone else can chime in here but I don't think it is possible to perform EAP-Chaining with the internal database of ISE. With that being said, feel free to read the EAP-TEAP IETF doc :)


That's what I was suspecting.... shame....

And what about making an identity MAC vs User is that possible?

Sorry for the delay as I was out of town for training. Can you elaborate a bit more on what you mean by "making an identity MAC vs User?"

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers