07-03-2017 02:31 AM
Hello together,
I have configured a wired LAN authentication and I have fully configured the switches, the policies are according to documentations and everything I could think of seems to be set correctly.
Now the issue is, when I connect my devices (using LAN cables) to the switches, the default policy is being selected (see Screenshot -> Authentication Policy), even though "Radius NAS-PORT-TYPE = Ethernet & Device Type = Device Group Switches (my radius switches)!
Question: How do I disable the default policy or how to ensure that my wired policy is always used for wired dot1x?
Solved! Go to Solution.
07-03-2017 06:28 AM
I suggest the following configuration :
Also:
Configure the Authorization Plicy like that: AthZ_Policy_Name if Any and
CERTIFICAT: Subject Alternative Name – DNS contains “your_domain”
Network Access: AuthenticationMethod Equals X509_PKI
RADIUS: NAS-Poirt-Type Equals ETHERNET
Then: Admin_Wired
I hope that will help.
Best regards
07-03-2017 05:27 AM
Hi Kadir
The Policy Sets in ISE are like the Service Selection Policy on ACS. The order is very important.
Please place you Policy Set "Access Wired" before the Default Policy Set.
Best regards
07-03-2017 05:41 AM
Hello Abdollah,
I have moved around the policy set from top to bottom...technically the "Access Wired" Policy set is at the very top, whereas the default policy set is at the bottom (not moveable anyway)...do you have another sugestions?
Kind regards,
Kadir
07-03-2017 05:47 AM
Hi Kadir
Please upload a screenshot of your Policy Sets on ISE. I can help based on what you have in your configuration.
Best regards
07-03-2017 05:51 AM
I hope this helps...let me know if required more...
07-03-2017 06:28 AM
I suggest the following configuration :
Also:
Configure the Authorization Plicy like that: AthZ_Policy_Name if Any and
CERTIFICAT: Subject Alternative Name – DNS contains “your_domain”
Network Access: AuthenticationMethod Equals X509_PKI
RADIUS: NAS-Poirt-Type Equals ETHERNET
Then: Admin_Wired
I hope that will help.
Best regards
07-03-2017 06:46 AM
The Admin_Wired must be configured like that :
Access Type = ACCESS_ACCEPT
VLAN Tag ID 1 and Name: YOUR_VLAN_NAME
You can also enable the rethentication after 1h (as an example):
Reauthentication Timer: 3600
Maintain Connectivity During Reauthentication RADIUS-Request
07-03-2017 07:57 AM
This was the right answer!
Thank you, it now does work after creating a new Policy Set and by using some of your suggested method.
However after removing the (Device Type = Device Group Switches) and only setting it to Network Access = Radius & Nas-Port-Type = Ethernet...it started Running again!
Thanks you all for the professional help!
07-03-2017 08:56 AM
Hi Kadir
I'm happy to know that you are able know to authenticate the users!
Best regards
07-03-2017 05:51 AM
07-03-2017 06:05 AM
Hello Danny,
even when I add the Service-Type = Framed it uses the default policy...I have multiple Policy sets however it's only the "Access Wired" which is not being recognized for some reason...(see screenshot)
07-03-2017 06:12 AM
I would remove radius attributes first and try to match based on your device type only, perhaps even narrow it down to a specific device your endpoint is hanging off of , keep it to a minimum and simple just to make sure you hit the policy set at first.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide