cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1810
Views
0
Helpful
8
Replies

Cisco ISE - Access-reject with dynamic Vlan - 802.1x wired with 2960x switches

illusion_rox
Level 1
Level 1

Dear Experts, 

 

Can you help to confirm that if user is trying to authenticate via wired port on 2960x but couldnt provide correct credentials, can we push back dynamic quarantine/guest vlan from ISE instead of configuring fallback vlan locally on the switch?

8 Replies 8

illusion_rox
Level 1
Level 1

My understanding is that, we need to pass vlan information in access-reject message.  can we do it using cisco ISE?

Attributes passed in RADIUS Access-Reject would be ignored by the switch, you need to create a new Authorization rule and pass Authorization profile that contains Access-Accept, but with a VLAN that you want the users to be put in. (You could also use the default rule)

Sir authorization would come into play after user is successfully authenticated. If user authentication fails can we still send access accept message?

Anyone pls?

You generally can't do that, except in specific scenarios with MAB

So its safe to say and convey to customer that for 802.1x authentication scenario this is not possible??

Yes, you can do this. There is an option to continue to Authorization if Authentication fails. Click on the identity store section under the Authc policy and you should see this option. See picture below.

authc-failed.PNG

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: