cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
2
Replies

Wired access for guests and employees without dot1x

ymadheka
Level 4
Level 4

Hi Folks,

In case of customer having a requirement of having the endpoints connected to the wired network without dot1x using passive identity (Easyconnect) can identify the AD user information for the connected endpoint. The concern is can ISE can check for the guest endpoint on the same / different port on the wired network since both will be using MAB as the authentication protocol.

Kindly advise.

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

Why not use CWA for guests?  This fits into typical config models where both 802.1X and MAB are configured with FlexAuth.  If one method fails, it falls back to other.  CWA is based on MAB auth method to allow secure access for guests as well as IoT endpoints.

/Craig

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

Yes.

When ISE not receiving user info from PassiveID, there is no session merge so the guest endpoints can continue with ISE guest flow. When ISE receiving PassiveID info, then it merges the session and provide Easy Connect access.

Craig Hyps
Level 10
Level 10

Why not use CWA for guests?  This fits into typical config models where both 802.1X and MAB are configured with FlexAuth.  If one method fails, it falls back to other.  CWA is based on MAB auth method to allow secure access for guests as well as IoT endpoints.

/Craig