cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2306
Views
0
Helpful
1
Replies

ISE failed authentication attempts

Daniel Matos
Level 1
Level 1

Hi!!

 

We are trying to do a ISE option, were after a X number of failed login attempts the user is send to a specific vlan named "quarantine" vlan, is it possible to do this via the policy sets?

 

ISE is configured to authenticate users via AD.

 

Thanks for the help!

1 Accepted Solution

Accepted Solutions

Mike.Cifelli
VIP Alumni
VIP Alumni
You have a couple of options. You could configure default ISE policies to push hosts/users to a restricted network. You could statically assign your interfaces on your NADs to authorize the attached host into a restricted network upon 8021x failure (authentication event fail action authorize vlan xx). If you are running IBNS you can create a template globally and assign to your interfaces that essentially would do that same thing as if you statically assigned ports. Some good stuff here: https://www.cisco.com/c/en/us/products/ios-nx-os-software/identity-based-networking-services/white-paper-listing.html

Good luck & HTH!

View solution in original post

1 Reply 1

Mike.Cifelli
VIP Alumni
VIP Alumni
You have a couple of options. You could configure default ISE policies to push hosts/users to a restricted network. You could statically assign your interfaces on your NADs to authorize the attached host into a restricted network upon 8021x failure (authentication event fail action authorize vlan xx). If you are running IBNS you can create a template globally and assign to your interfaces that essentially would do that same thing as if you statically assigned ports. Some good stuff here: https://www.cisco.com/c/en/us/products/ios-nx-os-software/identity-based-networking-services/white-paper-listing.html

Good luck & HTH!