04-29-2019 01:06 AM
Hi all,
I am trying to understand how switch 802.1X activation and impact on existing devices such as windows login to domain, door access, IP camera,etc.
1) First of all, all dump terminals connecting to switch(w/o 802.1x) is working fine now. Can I see those devices in ISE? Where?
2)After perform switch 802.1X activation, do I need to do any config change in ISE for these dump terminals?
3)Currently all windows workstation login to domain successfully. After perform switch 802.1X activation, is there any change in the way user logon to windows domain?
4)After perform switch 802.1X activation,is there any change of config tht i need to do for all 802.1x and non-802.1x devices?
5)If certain devices not in ISE but works fine before switch 802.1X activation and doesnt work after 802.1X activation, where can I find those devices and is there any config change tht I need to do?
Many thanks for all info.I am trying to understand the process and user experience before and after 802.1X
Solved! Go to Solution.
04-29-2019 01:05 PM
Without 802.1X: the user plugs into the switchport and gets instant access.
With 802.1X: the user's supplicant is challenged for authentication and assuming they pass authentication, they are allowed access.
The exact behavior depends on many things on the endpoint which ISE does not control:
So, It Depends. Please be extremely specific about the details of your scenario.
04-29-2019 04:56 AM
Please see our ISE secure Wired Access Deployment guide to get an understanding of the different authentication types provided and their behavior in a wired environment.
04-29-2019 06:12 AM
I have read lots of 802.1X docs. but i still cant find any tht explains user experiences Before and After configure switch 802.1X authentication.
04-29-2019 01:05 PM
Without 802.1X: the user plugs into the switchport and gets instant access.
With 802.1X: the user's supplicant is challenged for authentication and assuming they pass authentication, they are allowed access.
The exact behavior depends on many things on the endpoint which ISE does not control:
So, It Depends. Please be extremely specific about the details of your scenario.
04-30-2019 04:56 AM
Without 802.1X: the user plugs into the switchport and gets instant access.
With 802.1X: the user's supplicant is challenged for authentication and assuming they pass authentication, they are allowed access.
Currently all Windows PC Users login to domain using username & password. Is there any difference in the way user login to domain after switch activating 802.1X config? Can I say tht the above challenged authentication with switch 802.1X is provided when they login to their company domains?
Servers using CA certs. Other devices like cctv, printers using MAC address bypass i think.
Is there any difference for these devices after switch activating 802.1X config?
The exact behavior depends on many things on the endpoint which ISE does not control:
So, It Depends. Please be extremely specific about the details of your scenario.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide