ISE - WebAuth

For device doesn't support Dot1x, MAB can be used to authenticate with ISE, but MAB is not secure and it doesn't support user authentication. In case user authentication is required, WebAuth can be used along with MAB to allow user to enter their credential via Web.

CWA (Central Web Authentication) can be configured on ISE and NAC (switch and WLC).

In wired environment, a non-802.1X PC connects to a MAB enabled port, MAB authentication is initiated, on ISE, it first passes the wired MAB authentication, for authorization policy, its condition can be MAB and other requirement like office location, then the access profile defines a dCAL to be download to switch port, this dCAL also called Captive Portal dACL, which only allows web traffic, DNS and ISE portal access, also the redirect URL name will be sent to the switch, the URL must exists on the switch,  only the name is sent from ISE.

When the user login the non-802.1x enabled PC, opens the browser and type an url,  because  the Captive Portal dACL allows web traffic, the web traffic passes the switch port ACL hits switch http server, the http server has the redirect URL from ISE, so the connection is redirected to ISE portal. Once client successfully login, CoA is initiated, new dCAL and/or VLAN assignment will be downloaded to the switch.

Comments

Popular posts from this blog

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower FMC and FTD troubleshooting

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.