07-17-2006 04:14 PM - edited 03-10-2019 02:39 PM
Hi forum,
Is there a way to use Radius to authenticate users(based on windows user accounts) when they are connected to the switches before granting them access to the windows environment?
07-18-2006 02:19 AM
Hi
The most obvious solution would seem to be 802.1x port security. The switch then doesnt give any network access until the AAA server gives back a result.
You could use vlans from ACS so that authenticated users get onto the network where the windows servers reside, and everyone else gets dumped to somewhere else.
The switch needs a pre-configured username/password so that PCs without 802.1x configured can still be authenticated to receive the non-windows vlan assignment.
This stuff is all part of the NAC framework, although you dont need all the extra complexity of posture validation and stuff.
Darran
07-18-2006 05:38 PM
Hi Darran,
Thanks for your reply. I will explore the areas you mentioned.
Thanks much & Best regards,
Paul
07-19-2006 03:55 AM
Disregard above entry is correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide