08-20-2023 06:51 AM
Hello guys,
how can i enable a specific method list for dot1x auth/authz on cisco switches ?
Thanks
Solved! Go to Solution.
08-20-2023 07:57 AM
@ramziabdelhak check out the differentiated authentication section of this guide - https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515
You can apply different settings based on NAD/interface(s) directly using ISE authorisation rules rather than make the switch configuration overly complex.
08-20-2023 07:11 AM
@ramziabdelhak example:-
aaa authentication dot1x LIST group ISE aaa authorization network LIST group ISE
08-20-2023 07:47 AM
Hi @Rob Ingram
What i want to do, is to specify a named method list that do not apply authorization on specific switch interfaces having dotx enabled so that i can manuly apply my vlans once the enpoint got authenticated by ISE,
As usual, you are alway the first to help, thank you man
08-20-2023 07:57 AM
@ramziabdelhak check out the differentiated authentication section of this guide - https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515
You can apply different settings based on NAD/interface(s) directly using ISE authorisation rules rather than make the switch configuration overly complex.
08-21-2023 06:48 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide