cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
815
Views
5
Helpful
3
Replies

Pre-Authentication VLAN for ISE

fatalXerror
Level 5
Level 5

Hi Guys,

 

I have multiple production VLANs and I know ISE can enforced VLAN but I just thought how will the endpoint communicates to ISE if the endpoint does not have an IP address in its initial connection? How will ISE get an IP address in the DHCP server if ISE does not enforced yet which VLAN should the endpoint will be?

 

Thanks

1 Accepted Solution

Accepted Solutions

Hi,
It's the NAD (the switch) that communicates with the RADIUS server not the client directly. The client would not receive an IP address until after successful authentication.

HTH

View solution in original post

3 Replies 3

Hi,
It's the NAD (the switch) that communicates with the RADIUS server not the client directly. The client would not receive an IP address until after successful authentication.

HTH

Hi @Rob Ingram,

Thanks for the feedback.

If that is the case, what is the use of the pre-authentication ACLs? Just for redirection of traffic to CWA? What if, I am not using CWA just a simple authz policies, do I still need the ACLs?

Thanks

Hi,
If you are not using CWA then you would not need to define an ACL for CWA redirection on the switches.

HTH