cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
3
Replies

Partner wise WLAN Access Restriction through ISE

zunaid.cse
Level 1
Level 1

Requirement: Restrict Partner access to specific destination onl

Solution: Using WLAN with ISE you can restrict partner providing specific destination only

Step1: Create WLAN with Mac Filtering and Allow AAA Override should be enabled.(This should be enable in order to push Airspace ACL from ISE)

  Create ALC on WLAN which destination you want to apply.

Step 2: Create an Authorization policy

guest-redirect.JPG

Step 3: Create Local Identity Group with an user.

Go to Administration>Identity Management> Groups>User Identity Groups

Then create an local user in ISE selecting created user group.

Step 4: Create and authentication policy with Wireless MAB

Step 5:Then create an authentication policy

authz-policy.JPG

Here red marked option is created identity group.

Using this policy you can restrict onsite partner access where every partner will have respective destination access using same WLAN and Same source ip block.

Identity base ACL will pushed.

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

Hello, was this a question?

View solution in original post

3 Replies 3

howon
Cisco Employee
Cisco Employee

Hello, was this a question?

It was a solution

Yes its a question.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: