cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2643
Views
0
Helpful
1
Replies

ISE config with Mac filtering

Eric Lindsey
Level 1
Level 1

We are setting up ISE. I need to setup a rule that uses 802.1x authentication to authenticate a user plus the MAC address of the machine must be in an endpoint group and it has to be on a particular ssid. If the user is connecting to the wrong ssid or the Mac is in the wrong endpoint group it should fail to connect. Is that possible with ISE 2.0?

1 Reply 1

jj27
Spotlight
Spotlight

Yes, use endpoint identity group with the MAC address combined with a condition checking AD group membership and that the Airespace-WLAN-ID=xx or Radius Called Station ID ends with the SSID name in the authorization policy.