Which way to enforce policy for endpoint from gateway router instead of switch
Dear team,
I am proposing ISE to customer. They want to deploy ISE as central authentication and policy point for users in branches. I would like to ask if this scenario is possible or not:
- When user client is plugged into access switch, the switch will use 802.1x or MAB in switch port
- After authentication, as normal method, we will push a dACL or VLAN change from ISE to switch in authorization statements. But customer dont want to apply port ACL on switch. They want to enforce policy from the gateway Router.
So is there any way to do that? I'm thinking about SGT but I dont have any experience on it. Please help to solve this problem. Thank you very much.
Kind regards,
Hiep Nguyen.
Hiep,
You can use authentication proxy to push ACLs for users on the router. However the port based ACL is your best approach because you can determine authorization at the port level and if the user moves so does the policy.
thanks,
Tarik Admani
*Please rate helpful posts*
Similar Messages
-
Hello everybody out there.
Which way can I get the screensaver from Lion get back on Mountain Lion??
Thanks
malibu0978Thanks very much I have contacted them via this. Just hope they respond quickly- rather annoing! Greatly appreciated though
-
Which Image should we need for the below model router 2951 to support 4 Byte ASN number ?
Hi All,
Which Image should we need for the below model router 2951 to support 4 Byte ASN number ?
CISCO2951/K9
Cisco 2951 w/3 GE 4 EHWIC 3 DSP 2 SM 256MB CF 512MB DRAM IPB
PWR-2921-51-AC
Cisco 2921/2951 AC Power Supply
CAB-ACSA
AC Power Cord (South Africa) C13 BS 546 1.8m
HWIC-BLANK
Blank faceplate for HWIC slot on Cisco ISR
ISR-CCP-EXP
Cisco Config Pro Express on Router Flash
MEM-2951-512MB-DEF
512MB DRAM (1 512MB DIMM) for Cisco 2951 ISR (Default)
MEM-CF-256MB
256MB Compact Flash for Cisco 1900 2900 3900 ISR
SM-S-BLANK
Removable faceplate for SM slot on Cisco 290039004400 ISR
SL-29-IPB-K9
IP Base License for Cisco 2901-2951
S2951UK9-15501T
Cisco 2951 IOS UNIVERSAL
EHWIC-1GE-SFP-CU
EHWIC 1 port dual mode SFP(100M/1G) or GE(10M/100M/1G)> Can someone suggest ?
a forum is no realtime-communication ... ;-)
For the ISR G1, it was supported from 12.4(24)T, so I would assume that your ISR G2 has this feature if you are running 15.x.
EDIT: The Feature-navigator says that it's supported starting with 15.1(2)T. -
Best way to conditionally tag for translation from English to Spanish?
Is it best/more efficient to conditionally tag for translation from English to Spanish in structured FrameMaker or in Robohelp?
This is more info gathering at this point, full requirements are not yet defined. Definitely want the RH help translated; might also need the FM book translated, but not sure.
-
Tips for upgrading from LR2 to 3 while switching to a new computer?
My old mac was a G5 so I finally joined the modern world with a new iMac. On the new machine I've installed LR3, but I'm still running LR2 on the old machine. I want to bring all my pics/catalogs/dbs over (most likely by getting an external HD case for the current drive of the old machine) to the new machine and into LR2. Any tips on how to import everything? Anything to watch out for? I have thousands of images, some of it paid work, and I don't want to lose anything. Thanks.
Rule No. 1: DON'T IMPORT!!
This is what I would do:
On the old machine and LR2, make sure you have one (or just a few) top-level folders for all your images, and they are showing hierarchically in your folder panel. You might have to use "Add Parent Folder" a few times to achieve this.
With the old drive mounted on the new machine, double-click the LR2 catalog to start LR3
You will be asked if you want to convert your LR2 catalog into an LR3 catalog
Confirm this action, which will build a new LR3 catalog from your LR2 catalog, leaving the LR2 catalog as it is
If your folders/images show missing (which I'm not sure about on a Mac when the same volume is mounted as an external drive), perform a "Find missing folder" on all top-level folder(s) of your catalog, pointing to the folders on the mounted volume
If needed/wanted, you can then move the top-level image folders from within LR to a different volume
If you need/want to move the catalog as well, copy the "[catalogname].lrcat" file and the "[catalogname] Previews.lrdata" folder to a different drive when LR is closed, and restart LR by double clicking the copied .lrcat file
Delete the old catalog after you're sure the new one works to your satisfaction
You might also want to consider copying your presets, plugins and ACR defaults from the old machine to the new one.
Beat -
I want to know whether this is real or fake!
As I can't find the option "iTunes and App Store" in settings, which my iPhone 4S has.
This is an iPhone 5. Bought from china.
<Edited by Host>I have taken it back to the Apple store genius bar, but they say they don't see anything wrong. Well unless you use it all day and experience the problems when they happen, you wont see anything wrong. But there are lots wrong with it. But this would be the same store as I purchased the phone. And they backed up my old Iphone 4, but were not able to get anything to load back onto my new phone. So, I lost pretty much everything. But over time, some of my contacts have started showing up, although i am still missing over 800 of them.
-
Which way to get image for webi report?
Hi,
I have to add image to webi report. So any way is there for adding image for webi intelligence.check this thread:
Adding an image (logo) to webi report -
Why different ways to access options for tools?
Sometimes options for tools are in the Control panel, sometime you double click on the tool, and sometimes you double click on the Artboard?
Is there a reason it works this way? Just trying to understand the logic to make it easier to figure out which way to access options for which tools.
Thanks!Each area you sighted has different options. That's why they are different.
Items in the Control Bar are generally items you'll adjust per use.
Items by double-clicking the tool are generally set once per session, or once ever.
I don't know what you are referring to by "double-clicking the artboard" As far as I'm aware, that only enters or exits Isolation Mode. (And can be turned off in the preferences.) -
Copy 'Services for Objects' from Quote to Order
Can anyone tell me a way to copy 'Services for Object' from a Quote to an Order when the order is created via reference to the quote. For a simple case, lets say we have an excel sheet attached to the quote via/under Services for Objects. When we create a Sales Order with reference to that Quote I want the attached excel sheet to be visible under The 'Services for Object' of the Sales Order.
Thanks in advance.Hi Mohanpreet,
Have you craeted a new field BA for lead and activity?
Is it also present in quotation and sales order?
If the coupy contol from lead to opportunity does pass on the field details, they must also get transfered from opportunity to quotation and sales order. Maintain the copy contro settings properly.
If the issue is still not resolved use BADI CRM_COPY_BADI for further enhancements.
Wish this is helpful.
Regards,
Shalini Chauhan -
Which function module is used for transfering form one version to another
HI
COULD ANYBODY TEL ME
WHICH FUNCTION MODULE IS USED FOR TRNASFORING FROM ONE VERSION TO ANOTHER VERSION.................Hi Chaithu,
Go to SE37,enter your function module, click on where used list button on the application bar.
All the program used your function module used is displayed.
Regards,
Venkat. -
Any way to use merge for mutliple tables w/ shared PK?
If you have multiple tables who share the same PK (or I should say the main table has a certain valye used as Primary Key and then multiple child tables use that PK as a foreign key), would merge be able to work for you?
in my case I have one source table, which is loaded by flat file and represents a flattened record of what would in my database be separated into multiple tables.
I need to update records from that source table where they exist (based on join of non-PK columns) and then insert where they do not exist. So I thought I could utilize the nifty merge command.
However I am quickly realizing this is not a standard use of merge which seems to be designed for going from one source table to one target tables which are roughly equivalent. But in my case I have one source table which has pieces going into table A, other pieces table B, etc... and all those tables share an ID.
So when I first merge into the main table I use a sequence to generate it's PK. But then the problem becomes, how do I then have this same PK used as the value for the FK in the inserts done by the following merge commands for this child tables?trant wrote:
If you have multiple tables who share the same PK (or I should say the main table has a certain valye used as Primary Key and then multiple child tables use that PK as a foreign key), would merge be able to work for you?
in my case I have one source table, which is loaded by flat file and represents a flattened record of what would in my database be separated into multiple tables.
I need to update records from that source table where they exist (based on join of non-PK columns) and then insert where they do not exist. So I thought I could utilize the nifty merge command.
However I am quickly realizing this is not a standard use of merge which seems to be designed for going from one source table to one target tables which are roughly equivalent. But in my case I have one source table which has pieces going into table A, other pieces table B, etc... and all those tables share an ID.
So when I first merge into the main table I use a sequence to generate it's PK. But then the problem becomes, how do I then have this same PK used as the value for the FK in the inserts done by the following merge commands for this child tables?realize that everyone here speaks SQL
I could better understand what you have & what you desire if you post DDL for all tables
& then you explain what is desired using actual table & column names.
Simply put, I would not recognize any post SQL as being correct, since I do not understand the desired goal/results -
How to copy a configuration from one router to another?
Hi I have a 2600 that I need to use for a new gateway router. I need to copy the configuration from the old router to this one. I need to know how to do that the fastest way. If someone can help it would be appreciated. Thanks.
well i have this in mind which may help you.
You would need to have a public ip address to the machine you have consoled to and on internet.
Download the tftp software from below link.
http://tftpd32.jounin.net/
This software does not only act as the tftp server but also you can select the interface of you ethernet card as tftp server ip address.
For ex if you are connected to a console and have a wireless card which is connected to internet also you connect you eth lan card to the eth or fast eth of the router.
you can select which ever interface you want to act as the tftp server.
you will need to add ip addres for you lan card and also config the router port as same if needed. -
DVD to i-Pod from Gateway Media Center
Is there a way to download a movie DVD from Gateway Media Center to i-Pod???
You don't.
you have to put the music in itunes and sync it from there. -
What are the correct settings for my wireless-n router?
I was just upgraded at home with a Huawei HG8245 Fiber Optic Wireless-N router. The default Setting is:
WPA/WPA2 Pre-Share, TKIP/AES, Auto Channel and 20Mhz Channel Width.
I cannot surf past 10 feet from the router. I switched the Security to TKIP, and it goes to Wireless-G and I can surf all around my apartment. I did AES only, goes back to Wireless-N, and again the 10 feet issue. Selected WPA2 only...same thing.
Any ideas or solutions?
PaulI have opened ports 80, 443,and 4125 to PCP. The router address is http://192.168.1.1, my address is 221.40.138.170.
Thank you. -
is there a way to sync my music from my ipod touch to a computer without using other computers? because i lost my computer which has all the data for my ipod touch
See also Recover your iTunes library from your iPod or iOS device.
tt2
Maybe you are looking for
-
Your software may not recognize the question, but that's pretty much all I can tell you in the absence of a specific question.
-
How to get Source code of a Schedular Java concurrent program in Payments
Hi Experts, I am very new to Java Concurrent program. I need java source code of a schedule java concurrent program.Following are the details of Executable. Executable :Format Payment Instructions Short Name :IBY_FD_PAYMENT_FORMAT Application : Payme
-
Hi all, I have videos that I downloaded from my camera to iPhoto on my main computer(upstairs). But when I go to my other computer(downstairs) and open iPhoto to look at the shared library from the main computer, the movies don't show up. On
-
Error: Item(s) was/were not activated due to online payment block
Hi, I have an issue with F-58 transaction. When i try processing an open line item of the vendor (in F-58) i get an error "1 item(s) was/were not activated due to online payment block". Please advise as to how i can locate the issue. Thanks, Safi
-
How can I take Smileys to a calendar in Iphoto? Hur kan jag placera Smileys i en kalender jag håller på att göra i Iphoto?