10-11-2016 01:14 PM
My customer is a Core Banking Solution provider they manage the DC service and the branches are managed by Banks.
Customer is looking for NAC solution which can be implemented in the DC without touching the branches.
I am looking for pointers on how can we use ISE to only allow domain Users on authorized machines only.
All other personal or unauthorized laptops to be blocked.
Solved! Go to Solution.
10-17-2016 02:19 PM
Please see the latest ISE Compatibility Guide for supported network access devices.
ISR 8xx have relatively poor ISE feature support on switchports beyond basic 802.1X and TrustSec:
If they don't own/manage the ISR800's it doesn't really matter since you will have no way to configure and manage the endpoint at the edge 8-(
10-13-2016 06:48 AM
Use AD as the ID sources and check AD group memberships to allow only domain users. Use ISE profiling and/or ISE posture to enforce on authorized machines. If Windows, then it's possible to use EAP Chaining to check both user and machine identities via EAP-FAST. Another option is to use CWA chaining.
10-13-2016 06:55 AM
Hi
Will this work without any control on access switches? Customer wants the solution to work with end user machines only and ise being deployed at data center
The branch network is not under his control
10-17-2016 02:19 PM
Please see the latest ISE Compatibility Guide for supported network access devices.
ISR 8xx have relatively poor ISE feature support on switchports beyond basic 802.1X and TrustSec:
If they don't own/manage the ISR800's it doesn't really matter since you will have no way to configure and manage the endpoint at the edge 8-(
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide