11-19-2015 07:53 PM - edited 03-10-2019 11:15 PM
Hi experts,
I have got the following network in brief:
Devices -> Access Switch -> Core Switch -> Access Switch -> ISE Server
All switches are IOS capable for the 802.1X and AAA configurations for ISE to manage the network devices. However, I have read through guide on the switches configuration in preparation for CIsco ISE deployment but I am just wondering do I need to configure both access switches and Core switches or do I only configure the access switches for ISE?
Thanks for your time reading!
Solved! Go to Solution.
11-22-2015 08:14 PM
If all the clients are non-DHCP clients, then there is no configuration on core or distribution at all.
But you may need to look out for different profiling options if the clients are not DHCP enabled. Does the access switch support IOS sensor function? Would be very useful to have one as it would send important profiling information to ISE. You may need to use a right profiling options for ISE to determine the endpoint details.
Regards
Vivek
11-20-2015 03:04 AM
Hi,
To authenticate clients you only need to configure the device (NAS) that will be passing the radius packet to your ISE (radius server) often secured by way of a mutually configured secret key on both devices (authenticator and the authentication server) .
An example of a NAS would be access switch, WLC.
11-22-2015 07:34 PM
Hi Marcus,
It depends on your network design. If all the endpoints gets connected to access switch only, then the major piece of configuration goes on the access switch. Depending on our profiling setup on ISE, if you are using a DHCP profiling option, then you need to ensure that the ISE PSN IP or virtual IP (if Load balanced), is configured as a IP helper on the L3 SVI which might be on your Core switch.
Hope this helps.
Regards
Vivek
11-22-2015 07:56 PM
11-22-2015 08:14 PM
If all the clients are non-DHCP clients, then there is no configuration on core or distribution at all.
But you may need to look out for different profiling options if the clients are not DHCP enabled. Does the access switch support IOS sensor function? Would be very useful to have one as it would send important profiling information to ISE. You may need to use a right profiling options for ISE to determine the endpoint details.
Regards
Vivek
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide