cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
683
Views
8
Helpful
6
Replies

NAC Policy for OS Boot vs Initial Boot

Folks,
I needed some suggestion on Policies getting applied when the 802.1x authentication kicks in vs Initial Boot by a system.

Our policies say that once the 802.1x authentication succeeds allow the machine to get authorized on the "Employee VLAN". This policy works just fine, but the catch here is when the system performs an initial boot the system does not get in the "Employee VLAN", which is expected as the OS cannot perform a 802.1x authentication.

Any suggestions to overcome this challenge?


Thanks!
N.

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

You mean PXE boot ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi BB,
No not PXE boot. This is just the initial boot screen, i.e. when the Laptop is first powered on.
(Or for that matter it is left idle for some time....even here we seen at times the "Employee VLAN" gets lost and the Laptop for in the "Guest VLAN")

Thanks!
N

I assume you are doing user auth?  If so there is no 802.1X transaction by design until a user logs into the system.  You should also enable machine authentication if you need to provide network access before login.  That being said, why change VLANs at all?  Why not use a dACL or some other enforcement method?

@ahollifield : Thanks for the answer and apologies for the late response.
Any details you can share on machine authentication? This is new to us and would like to check how this can work.
Thanks a ton.

Regards,

N!

These are windows endpoints correct?  If so enable "Computer Authentication" in the supplicant configuration.  

hslai
Cisco Employee
Cisco Employee