cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
509
Views
0
Helpful
2
Replies

ISE Posture in FlexConnect

i_mohamed
Level 1
Level 1

Hello All,

I have a customer who has many branches with 2 o 3 APs in each branch. They also already have ISE. They have specific requirements:

1- Local DHCP services in each branch (not centralized).

2- They need to locally switch/bridge the traffic inside the branch and not tunnel it centrally to the main site/DC/Controller.

3- They need to apply ISE Posture health check on clients using AnyConnect client.

With FlexConnect mode of APs (default is connected mode - i.e. in normal situation connection is up to centralized 9800 Controller).

Is this doable? if yes, what are the limitations? any issues with DHCP & VLAN assignment?

Thanks

2 Replies 2

marce1000
VIP
VIP

 

  1) and 2) are kind of standard features of 9800 when APs are configured in Flexconnect mode 
  3) Is in essence not related to wireless but Anyconnect , (but) have the ISE posturing policy enforced on the VPN server where the Anyconnect client connects to.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

So, i saw in the WLC configuration guide the following constrain:

• FlexConnect APs do not forward the DHCP packets after Change of Authorization (CoA) and change of VLANs using 802.1x encryption. You must disconnect the client from the WLAN and reconnect the client to enable the client to get an IP address in the second VLAN.

I assume that the scenario will apply in my case here, since in the posture process the user connects initially to a VLAN (unhealthy) then connects to another VLAN when posture is ok.

Review Cisco Networking for a $25 gift card