Wireless FlexConnect and ISE

Domain Machine & User  Authentication and Authorization with Flexonnect Certral Switching


1. When the domain PC boot up, the PC will use domain computer account to connect to 802.1x WLAN if it is configured with "automatically connect" previously.

2. Controller interface can have a default ACL, when ISE authorization profile specify an Airespace ACL, for a wireless session, the default ACL will be replaced with the Airespace ACL . This Airespace ACL mush exists on the WLC, ISE only sends the ACL name.
Normally this Airespace ACL only allows DNS/DHCP and deny everything else.

3. When an domain user login the PC, an user authentication request is sent to ISE, By checking the user's AD group, ISE authorization profile can assign a new Airespace ACL, then CoA is sent to WLC, WLC replace the ACL on client's session.


Comments

Popular posts from this blog

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.

Firepower FMC and FTD troubleshooting