02-18-2021 06:36 AM
Is it possible to configure a pre-authentication ACL for interfaces configured with wired 802.1x authentication? I would like to have selective network access allowed in the state prior to successful authentication, and then overridden by a dACL granting full access if/when authentication passes.
Solved! Go to Solution.
02-18-2021 10:47 AM
No. You can just change the VLAN.
02-18-2021 10:47 AM
No. You can just change the VLAN.
02-18-2021 02:48 PM
Okay. Is any traffic at all (DHCP / DNS / PXE / etc.) allowed to pass on the switchport prior to authentication? Or is an unauthenticated endpoint completely isolated?
02-18-2021 02:51 PM
Completely isolated unless you configure a guest VLAN and authentication does not occur.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide