ā01-16-2025 04:27 AM
Hi folks,
One of my customers is planning to place ISE to implement 802.1x and posture assessment with agent. They have 9800 WLCs in datacenter, which manage APs in number of locations. If APs worked in local (tunnel) mode through WLC, posture assessment would be easy; because WLC would be managing everything. However, APs are working in FlexConnect Local Switching mode. Is there a way to do posture assessment in this scenerio without needing anything else? If yes, who handles authentication, authorization and CoA sessions? Is it AP? If it is AP, then is AP's model important?
Thanks in advance
ā01-16-2025 04:33 AM
You can use
Central authentication
This make AP local switching and central authc.
For CoA I will check be I think it work with central Authc.
MHM
ā01-16-2025 04:35 AM - edited ā01-16-2025 04:35 AM
What if you have Flexconnect local switching access points and WLANs? The previous sections are still valid. However, you need an extra step in order to push the redirect ACL to the APs in advance.""
MHM
ā01-16-2025 05:15 AM
Thank you @MHM Cisco World for the answer.
I am wondering about posture flow handling after provisioning client for agent. Is that only managed by wlc regardless of AP model (2702, 2802, 9115 in my deployment) in FlexConnect mode? I am worrying if posture state changing, CoA process, authentication and authorization can be sent and applicable in remote site, and worrying ap's inadequacy in a situation that it must be handling.
ā01-16-2025 05:26 AM
Add new ssid fo test apply step I share in link' and check posture.
I do think it will work.
Please update me
Thanks
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide