11-07-2019 06:01 AM
Hello,
I have a Customer that uses different PCs registered to different MS Active Directory domains (with no trust between each other) on the same LAN.
I know that ISE can connect up to 50 isolated MS AD domains, but I would like to confirm that this is correctly handled in SDA fabric and there are no caveats on this kind of config.
Thank you,
Luca
11-07-2019 12:04 PM
11-08-2019 12:21 AM
Thank you, haddo.
Is this completely transparent to SDA fabric and DNAC in the SGT policies and so on?
Cheers,
Luca
11-08-2019 06:01 AM
Not exactly sure what you mean by "transparent". In general, authentication (via AD or any other identity source) is separate from policy. You can however based SGT assignment based on which AD group the user is a member of.
HTH,
Fay-Ann
11-08-2019 09:25 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide