07-30-2013 09:40 AM - edited 03-10-2019 08:42 PM
I am implementing ISE and have run into several locations that have used consumer brand 4 ports switches to connect multiple workstations on one cable. I realize there is a list of supported Cisco switches for ISE, but I was wondering if anyone has used a lower end Cisco or other vendor switch (i.e. Cisco SG200-08 or SF300-08) to do basic authentication against ISE as it relates to enabling the port once the 802.1x authenitcation is passed?
Realize this is a bit vague, just looking for anyone with practical experience with this.
Thanks
07-30-2013 10:34 AM
I have not configured dot1x for the mentioned switches, if the switches do support dot1x you should be able to do basic authentication. If there are multiple endpoints on the same port, you should use the Multi-Auth host mode on switchport. Also you will have to choose an authentication method that is supported by the endpoints.
http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps11229/data_sheet_c78-634369.html
• Network security: Cisco 200 Series switches provide basic security and network management features you need to maintain a level of security for your business, keep unauthorized users off the network, and protect your business data. The switches provide integrated network security to reduce the risk of a security breach, with IEEE 802.1X port security to control access to your network.
and
802.1X: RADIUS authentication and accounting, MD5 hash
There wont be CoA and authorization, you may apply manual ACL on switchport for the controlled access.
the answer to your post, yes you should be able to do basic dot1x authentication.
HTH
07-30-2013 07:08 PM
I agree with Mudasir that " If the switches do support dot1x you should be able to do basic authentication. If there are multiple endpoints on the same port, you should use the Multi-Auth host mode on switchport. "
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide