cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1726
Views
1
Helpful
5
Replies

ISE Posture in FlexConnect

i_mohamed
Level 1
Level 1

Hello All,

I have a customer who has many branches with 2 o 3 APs in each branch. They also already have ISE. They have specific requirements:

1- Local DHCP services in each branch (not centralized).

2- They need to locally switch/bridge the traffic inside the branch and not tunnel it centrally to the main site/DC/Controller.

3- They need to apply ISE Posture health check on clients using AnyConnect client.

With FlexConnect mode of APs (default is connected mode - i.e. in normal situation connection is up to centralized 9800 Controller).

Is this doable? if yes, what are the limitations? any issues with DHCP & VLAN assignment?

Thanks

5 Replies 5

Mark Elsen
Hall of Fame
Hall of Fame

 

  1) and 2) are kind of standard features of 9800 when APs are configured in Flexconnect mode 
  3) Is in essence not related to wireless but Anyconnect , (but) have the ISE posturing policy enforced on the VPN server where the Anyconnect client connects to.

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

So, i saw in the WLC configuration guide the following constrain:

• FlexConnect APs do not forward the DHCP packets after Change of Authorization (CoA) and change of VLANs using 802.1x encryption. You must disconnect the client from the WLAN and reconnect the client to enable the client to get an IP address in the second VLAN.

I assume that the scenario will apply in my case here, since in the posture process the user connects initially to a VLAN (unhealthy) then connects to another VLAN when posture is ok.

n_nmanzoor
Level 1
Level 1

Hi 

any response to the query raised by @i_mohamed  ? I am too facing a similar situation; any solution would be much appreciated

thanks in advance!

 

 

@n_nmanzoor  Have you reviewed https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213924-flexconnect-wlan-with-802-1x-aaa-overrid.html?

n_nmanzoor
Level 1
Level 1

thanks @Rich R for sharing the link - let me go through this and come back !

Review Cisco Networking for a $25 gift card