Which way to enforce policy for endpoint from gateway router instead of switch

Dear team,
I am proposing ISE to customer. They want to deploy ISE as central authentication and policy point for users in branches. I would like to ask if this scenario is possible or not:
- When user client is plugged into access switch, the switch will use 802.1x or MAB in switch port
- After authentication, as normal method, we will push a dACL or VLAN change from ISE to switch in authorization statements. But customer dont want to apply port ACL on switch. They want to enforce policy from the gateway Router.
So is there any way to do that? I'm thinking about SGT but I dont have any experience on it. Please help to solve this problem. Thank you very much.
Kind regards,
Hiep Nguyen.

Hiep,
You can use authentication proxy to push ACLs for users on the router. However the port based ACL is your best approach because you can determine authorization at the port level and if the user moves so does the policy.
thanks,
Tarik Admani
*Please rate helpful posts*

Similar Messages

  • Hello everybody out there, which way can I get the screensaver from Lion get back on Mountain Lion??

    Hello everybody out there.
    Which way can I get the screensaver from Lion get back on Mountain Lion??
    Thanks
    malibu0978

    Thanks very much I have contacted them via this. Just hope they respond quickly- rather annoing! Greatly appreciated though

  • Which Image should we need for the below model router 2951 to support 4 Byte ASN number ?

    Hi All,
    Which Image should we need for the below model router 2951 to support 4 Byte ASN number ?
    CISCO2951/K9
    Cisco 2951 w/3 GE 4 EHWIC 3 DSP 2 SM 256MB CF 512MB DRAM IPB
    PWR-2921-51-AC
    Cisco 2921/2951 AC Power Supply
    CAB-ACSA
    AC Power Cord (South Africa) C13 BS 546 1.8m
    HWIC-BLANK
    Blank faceplate for HWIC slot on Cisco ISR
    ISR-CCP-EXP
    Cisco Config Pro Express on Router Flash
    MEM-2951-512MB-DEF
    512MB DRAM (1 512MB DIMM) for Cisco 2951 ISR (Default)
    MEM-CF-256MB
    256MB Compact Flash for Cisco 1900 2900 3900 ISR
    SM-S-BLANK
    Removable faceplate for SM slot on Cisco 290039004400 ISR
    SL-29-IPB-K9
    IP Base License  for Cisco 2901-2951
    S2951UK9-15501T
    Cisco 2951 IOS UNIVERSAL
    EHWIC-1GE-SFP-CU
    EHWIC 1 port dual mode SFP(100M/1G) or GE(10M/100M/1G)

    > Can someone suggest ?
    a forum is no realtime-communication ... ;-)
    For the ISR G1, it was supported from 12.4(24)T, so I would assume that your ISR G2 has this feature if you are running 15.x.
    EDIT: The Feature-navigator says that it's supported starting with 15.1(2)T.

  • Best way to conditionally tag for translation from English to Spanish?

    Is it best/more efficient to conditionally tag for translation from English to Spanish in structured FrameMaker or in Robohelp?

    This is more info gathering at this point, full requirements are not yet defined. Definitely want the RH help translated; might also need the FM book translated, but not sure.

  • Tips for upgrading from LR2 to 3 while switching to a new computer?

    My old mac was a G5 so I finally joined the modern world with a new iMac. On the new machine I've installed LR3, but I'm still running LR2 on the old machine. I want to bring all my pics/catalogs/dbs over (most likely by getting an external HD case for the current drive of the old machine) to the new machine and into LR2. Any tips on how to import everything? Anything to watch out for? I have thousands of images, some of it paid work, and I don't want to lose anything. Thanks.

    Rule No. 1: DON'T IMPORT!!
    This is what I would do:
    On the old machine and LR2, make sure you have one (or just a few)  top-level folders for all your images, and they are showing  hierarchically in your folder panel. You might have to use "Add Parent  Folder" a few times to achieve this.
    With the old drive mounted on the new machine, double-click the LR2 catalog to start LR3
    You will be asked if you want to convert your LR2 catalog into an LR3 catalog
    Confirm this action, which will build a new LR3 catalog from your LR2 catalog, leaving the LR2 catalog as it is
    If your folders/images show missing (which I'm not sure about on a Mac when the same volume is mounted as an external drive), perform a "Find missing folder" on all top-level folder(s) of your catalog, pointing to the folders on the mounted volume
    If needed/wanted, you can then move the top-level image folders from within LR to a different volume
    If you need/want to move the catalog as well, copy the "[catalogname].lrcat" file and the "[catalogname] Previews.lrdata" folder to a different drive when LR is closed, and restart LR by double clicking the copied .lrcat file
    Delete the old catalog after you're sure the new one works to your satisfaction
    You might also want to consider copying your presets, plugins and ACR defaults from the old machine to the new one.
    Beat

  • HT3939 A5****7CB this is my iPhone serial number, which my friend has bought for me from china. It was sealed pack. But now I have problem operating my phone. As I can't change the language of App Store. Secondly there is no option in setting where I can

    I want to know whether this is real or fake!
    As I can't find the option "iTunes and App Store" in settings, which my iPhone 4S has.
    This is an iPhone 5. Bought from china.
    <Edited by Host>

    I have taken it back to the Apple store genius bar, but they say they don't see anything wrong. Well unless you use it all day and experience the problems when they happen, you wont see anything wrong. But there are lots wrong with it. But this would be the same store as I purchased the phone. And they backed up my old Iphone 4, but were not able to get anything to load back onto my new phone. So, I lost pretty much everything. But over time, some of my contacts have started showing up, although i am still missing over 800 of them.

  • Which way to get image for webi report?

    Hi,
    I have to add image to webi report. So any way is there for adding image for webi intelligence.

    check this thread:
    Adding an image (logo) to webi report

  • Why different ways to access options for tools?

    Sometimes options for tools are in the Control panel, sometime you  double click on the tool, and sometimes you double click on the Artboard?
    Is there a reason it works this way?  Just trying to understand the logic to make it easier to figure out which way to access options for which tools.
    Thanks!

    Each area you sighted has different options. That's why they are different.
    Items in the Control Bar are generally items you'll adjust per use.
    Items by double-clicking the tool are generally set once per session, or once ever.
    I don't know what you are referring to by "double-clicking the artboard" As far as I'm aware, that only enters or exits Isolation Mode. (And can be turned off in the preferences.)

  • Copy 'Services for Objects' from Quote to Order

    Can anyone tell me a way to copy 'Services for Object' from a Quote to an Order when the order is created via reference to the quote. For a simple case, lets say we have an excel sheet attached to the quote via/under Services for Objects. When we create a Sales Order with reference to that Quote I want the attached excel sheet to be visible under The 'Services for Object' of the Sales Order.
    Thanks in advance.

    Hi Mohanpreet,
    Have you craeted a new field BA for lead and activity?
    Is it also present in quotation and sales order?
    If the coupy contol from lead to opportunity does pass on the field details, they must also get transfered from opportunity to quotation and sales order. Maintain the copy contro settings properly.
    If the issue is still not resolved use BADI CRM_COPY_BADI for further enhancements.
    Wish this is helpful.
    Regards,
    Shalini Chauhan

  • Which function module is used for transfering form one version to another

    HI
    COULD ANYBODY TEL ME
    WHICH FUNCTION MODULE IS USED FOR TRNASFORING FROM ONE VERSION TO ANOTHER VERSION.................

    Hi Chaithu,
    Go to SE37,enter your function module, click on where used list button on the application bar.
    All the program used your function module used is displayed.
    Regards,
    Venkat.

  • Any way to use merge for mutliple tables w/ shared PK?

    If you have multiple tables who share the same PK (or I should say the main table has a certain valye used as Primary Key and then multiple child tables use that PK as a foreign key), would merge be able to work for you?
    in my case I have one source table, which is loaded by flat file and represents a flattened record of what would in my database be separated into multiple tables.
    I need to update records from that source table where they exist (based on join of non-PK columns) and then insert where they do not exist. So I thought I could utilize the nifty merge command.
    However I am quickly realizing this is not a standard use of merge which seems to be designed for going from one source table to one target tables which are roughly equivalent. But in my case I have one source table which has pieces going into table A, other pieces table B, etc... and all those tables share an ID.
    So when I first merge into the main table I use a sequence to generate it's PK. But then the problem becomes, how do I then have this same PK used as the value for the FK in the inserts done by the following merge commands for this child tables?

    trant wrote:
    If you have multiple tables who share the same PK (or I should say the main table has a certain valye used as Primary Key and then multiple child tables use that PK as a foreign key), would merge be able to work for you?
    in my case I have one source table, which is loaded by flat file and represents a flattened record of what would in my database be separated into multiple tables.
    I need to update records from that source table where they exist (based on join of non-PK columns) and then insert where they do not exist. So I thought I could utilize the nifty merge command.
    However I am quickly realizing this is not a standard use of merge which seems to be designed for going from one source table to one target tables which are roughly equivalent. But in my case I have one source table which has pieces going into table A, other pieces table B, etc... and all those tables share an ID.
    So when I first merge into the main table I use a sequence to generate it's PK. But then the problem becomes, how do I then have this same PK used as the value for the FK in the inserts done by the following merge commands for this child tables?realize that everyone here speaks SQL
    I could better understand what you have & what you desire if you post DDL for all tables
    & then you explain what is desired using actual table & column names.
    Simply put, I would not recognize any post SQL as being correct, since I do not understand the desired goal/results

  • How to copy a configuration from one router to another?

    Hi I have a 2600 that I need to use for a new gateway router. I need to copy the configuration from the old router to this one. I need to know how to do that the fastest way. If someone can help it would be appreciated. Thanks.

    well i have this in mind which may help you.
    You would need to have a public ip address to the machine you have consoled to and on internet.
    Download the tftp software from below link.
    http://tftpd32.jounin.net/
    This software does not only act as the tftp server but also you can select the interface of you ethernet card as tftp server ip address.
    For ex if you are connected to a console and have a wireless card which is connected to internet also you connect you eth lan card to the eth or fast eth of the router.
    you can select which ever interface you want to act as the tftp server.
    you will need to add ip addres for you lan card and also config the router port as same if needed.

  • DVD to i-Pod from Gateway Media Center

    Is there a way to download a movie DVD from Gateway Media Center to i-Pod???

    You don't.
    you have to put the music in itunes and sync it from there.

  • What are the correct settings for my wireless-n router?

    I was just upgraded at home with a Huawei HG8245 Fiber Optic Wireless-N router.  The default Setting is:
    WPA/WPA2 Pre-Share, TKIP/AES, Auto Channel and 20Mhz Channel Width.
    I cannot surf past 10 feet from the router.  I switched the Security to TKIP, and it goes to Wireless-G and I can surf all around my apartment.  I did AES only, goes back to Wireless-N, and again the 10 feet issue.  Selected WPA2 only...same thing.
    Any ideas or solutions?
    Paul

    I have opened ports 80, 443,and 4125 to PCP.  The  router address is http://192.168.1.1, my address is 221.40.138.170.
    Thank you.

  • Is there a way to sync my music from my ipod touch to a computer without using other computers? because i lost my computer which has all the data for my ipod touch

    is there a way to sync my music from my ipod touch to a computer without using other computers? because i lost my computer which has all the data for my ipod touch

    See also Recover your iTunes library from your iPod or iOS device.
    tt2

Maybe you are looking for