cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3041
Views
10
Helpful
2
Replies

Question about 802.1x and DACL

jeremytetart
Level 1
Level 1

Hi Guys,

 

After read some Cisco documentation, I have questions for you about the relation between 802.1x and DACL.

 

If I want to push DACL on a Cisco Switch from ISE node, do I need to enable 802.1x command on the switch ?

 

In fact, I'm asking me which command is pre-requisite for enable DACL on Cisco switch ?

 

I know that the command ip device tracking is needed.

But do I need to run these commands :

  1. dot1x system-auth-control
  2. radius-server vsa send authentication
  3. radius-server vsa send accounting
  4. radius-server attribute 6/8/25

If someone can explain me which commands are a pre-requisite and which commands are optional and why ?

 

Regards.

1 Accepted Solution

Accepted Solutions

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

dACLs are being pushed by ISE following an authorization. This means you can have dACL for a VPN authorization, switch 802.1x authorization… In any ways, you will need to have an authorization going on.

 

All commands you mentioned are for 802.1x authentication. 

A good site to show what are all commands for for your knowledge: http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

2 Replies 2

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

dACLs are being pushed by ISE following an authorization. This means you can have dACL for a VPN authorization, switch 802.1x authorization… In any ways, you will need to have an authorization going on.

 

All commands you mentioned are for 802.1x authentication. 

A good site to show what are all commands for for your knowledge: http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thank Francesco for your reply ^^.