cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
292
Views
1
Helpful
1
Replies

Cisco NAC - DOT1x and MAB devices

Mat1992
Level 1
Level 1

Hello guys,

I'm struggling with one problem in our network
we have a Computers with certificates and we have an automation/rule in ISE which is working like this:
when the certificate is being found on the PC, the device is going to the Client vlan(offices etc) all MAB devices going to production,
but sometimes we need to keep some PC's with a certificate on the production.
In Cisco ISE we are selecting the correct identity group(for production) to given PC but ISE is still forcing such PC's to use Client Vlan do you know what we have to change ?

1 Accepted Solution

Accepted Solutions

pieterh
VIP
VIP

probably you just need to change priority / order of the policies/rules
and stop processing on first match
first - PC's with certificate + production group
then - PC's with certificate

View solution in original post

1 Reply 1

pieterh
VIP
VIP

probably you just need to change priority / order of the policies/rules
and stop processing on first match
first - PC's with certificate + production group
then - PC's with certificate

Review Cisco Networking for a $25 gift card