cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
321
Views
0
Helpful
1
Replies

802.1X ACL

dcanady55
Level 3
Level 3

Hello,

I have the following problem and I'm wondering if an ACL would be the best solution. We use 802.1X along with radius to an ACS box pointed to AD for authentication. In ports that have printers hanging off them we don't use 802.1X but rather sticky mac. The problem is folks don't realize we have port authentication/security and move around equipment and causes issues. I want to come up with a config where I use 802.1X on all ports and have the ability to plug printers in anywhere. I was thinking of setting up an ACL for this function as all printers need to have a static IP in a certain range and I could call out this range and provide access. I'm open for any suggestions on how best to set this up.

Thanks!

1 Reply 1

Borgenstrand
Level 1
Level 1

Hi,
In your case I would suggest to use 802.1x with MAC Authentication Bypass.
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-663759.html

Hopefully that will work for you. Good luck!