cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1021
Views
0
Helpful
3
Replies

Unique NAC Solution using ISE

Hemant Bharati
Cisco Employee
Cisco Employee

My customer is a Core Banking Solution provider they manage the DC service and the branches are managed by Banks.

Customer is looking for NAC solution which can be implemented in the DC without touching the branches.

I am looking for pointers on how can we use ISE to only allow domain Users on authorized machines only.

All other personal or unauthorized laptops to be blocked.

  1. Branches have only wired network
  2. Branches have ISR800M routers
1 Accepted Solution

Accepted Solutions

Please see the latest ISE Compatibility Guide for supported network access devices.

ISR 8xx have relatively poor ISE feature support on switchports beyond basic 802.1X and TrustSec:

ISR 88x, 89x Series

IOS 15.3.2T(ED)

!

X

!

X

X

If they don't own/manage the ISR800's it doesn't really matter since you will have no way to configure and manage the endpoint at the edge   8-(

View solution in original post

3 Replies 3

hslai
Cisco Employee
Cisco Employee

Use AD as the ID sources and check AD group memberships to allow only domain users. Use ISE profiling and/or ISE posture to enforce on authorized machines. If Windows, then it's possible to use EAP Chaining to check both user and machine identities via EAP-FAST. Another option is to use CWA chaining.

Hi

Will this work without any control on access switches? Customer wants the solution to work with end user machines only and ise being deployed at data center

The branch network is not under his control

Please see the latest ISE Compatibility Guide for supported network access devices.

ISR 8xx have relatively poor ISE feature support on switchports beyond basic 802.1X and TrustSec:

ISR 88x, 89x Series

IOS 15.3.2T(ED)

!

X

!

X

X

If they don't own/manage the ISR800's it doesn't really matter since you will have no way to configure and manage the endpoint at the edge   8-(