12-18-2018 01:15 PM
I have a customer that has 802.1x to ISE configured on his Meraki MS switches. They also have SXP configured between ISE and an upstream ISR router. They would like to configure SGACLs on the ISRs using the dynamically configured SGTs assigned in ISE, and publish these SGTs to the ISR router (SXP Listerner).
I guess the question is, can ISE create dynamic IP to SGT mapping using 802.1x from Meraki (not SXP speaker, because Meraki doesn't support it), and publish to an ISR via SXP?
Solved! Go to Solution.
12-18-2018 02:57 PM
In general this is supported, havn't actually integrated with Meraki.
If ISE is the one tagging 802.1x endpoints on Meraki then this should be possible.
Be sure to enable the below setting. This should populate the IP-SGT bindings on ISE with dynamic tags for radius sessions.
12-19-2018 10:24 AM
12-18-2018 02:57 PM
12-19-2018 10:24 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide