03-07-2019 06:24 AM
Hello,
I'm working on a windows radius server, and a cisco switch 2960X.
Is it possible to put the switchport as errdisable after the authentication fail ?
I tried to configure the port security but it does not see the authentication fail as an security violation.
So even when the authentication fail, it will still put the switchport on vlan1.
Thank you for your attention.
03-07-2019 08:25 AM
- In general this is not the intended purpose of ISE as this has more fundamental consequences for the device and it's network connection. You may want to look into schemes such as CoA, to isolate devices on quarantine VLAN's (that's only an example).
M.
03-11-2019 02:45 AM
03-11-2019 11:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide