Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
@parthrawat979
The ISE Wired Prescriptive Guide will cover all the switch related AAA commands for ISE https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515 the AAA commands haven't...
@zain-3-4 create the Endpoint Identity Group, add the MAC addresses. Edit your authorisation rule and add a condition "IdentityGroup:Name EQUALS GROUPNAME" and ExternalGroup EQUALS DOMAINNAME/OU/Group
@zain-3-4 Typically you would not bother with doing a MAC lookup and AD authentication, as you would have to manually update the MAC group membership and MAC addresses can easily be spoofed.
You could group the MAC addresses in ISE. In the authorisat...
@KayaaKashyap not with a policy based VPN, no. If you use a VTI (route based VPN) then you can use a loopback interface for the tunnel source, the IP address assigned to the loopback could be from a different subnet than assigned to the outside inter...