cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
618
Views
0
Helpful
1
Replies

Authentication for newly imaged workstation

nathsack
Cisco Employee
Cisco Employee

When a computer needs to be re-imaged remotely, is there a way to authenticate the newly imaged workstation on an internal LAN?  A dot1.x group policy needs to be applied to the workstation, but looking for a way to give the machine network access before getting the GPO pushed down.

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

What I do to facilitate this need is detailed below:

In the Policy Set for the 802.1x Wired Network, create an Authentication Rule for Wired_MAB. 

Wired_MAB.PNG

Then, for the Authorization Rule, place it just before the Default Rule and allow it to access specific network functions (DHCP, DNS, ISE, Image Server (or AD Domain Controller for Domain Joins).

Wired_MAB2.PNG

Line 1 is DHCP

Line 2 is DNS

Line 3 is ping

Line 4 is ISE

Line 5 is AD DC/Imaging Server

Wired_MAB3.PNG

This will allow for Domain Joins and re-imaging of machines, upon reboot and login, the GPO will be pushed to the client and then it's business as usual.

View solution in original post

1 Reply 1

Charlie Moreton
Cisco Employee
Cisco Employee

What I do to facilitate this need is detailed below:

In the Policy Set for the 802.1x Wired Network, create an Authentication Rule for Wired_MAB. 

Wired_MAB.PNG

Then, for the Authorization Rule, place it just before the Default Rule and allow it to access specific network functions (DHCP, DNS, ISE, Image Server (or AD Domain Controller for Domain Joins).

Wired_MAB2.PNG

Line 1 is DHCP

Line 2 is DNS

Line 3 is ping

Line 4 is ISE

Line 5 is AD DC/Imaging Server

Wired_MAB3.PNG

This will allow for Domain Joins and re-imaging of machines, upon reboot and login, the GPO will be pushed to the client and then it's business as usual.