Can Anyconnect be used for Macsec without needing an ISE?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-06-2016 12:23 AM - edited 02-21-2020 08:57 PM
Hi everyone,
If I wanted to deploy switch-host Macsec in my Windows domain, is it possible without deploying an ISE server?
I have Cisco ACS 5.x servers and 3850 switches, but most documentation I've come across delves into ISE regarding Macsec.
Moreover, is there any Cisco client which is specifically for Macsec without all the other features of Anyconnect?
Thanks in advance :)
- Labels:
-
AnyConnect
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-06-2016 05:32 AM
You can deploy AnyConnect with only the Network Access Manager (NAM) module. Then use the AnyConnect profile editor to define your wired network policy to include MACSec.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-06-2016 06:58 AM
Thanks for the quick reply. This setup requires only ACS as an authentication server, is this correct?
