cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
170
Views
2
Helpful
3
Replies

NAD config for 802.1x/MAB with ISE

babalao
Spotlight
Spotlight

Hello,

I have seen in several places this commands as best practice.

Are they still needed/helpful ?

-epm logging
-logging host <ISE_IP_address_x> transport udp port 20514
-epm access-control open or access-session acl default passthrough

-device classifier

 

thank you

regards

3 Replies 3

Arne Bier
VIP
VIP

Hello

 

-epm logging

Not required - legacy troubleshooting thing for very early ISE releases.


-logging host <ISE_IP_address_x> transport udp port 20514

Nope - that was a very early ISE requirement - but ISE will not enrich its Live Logs with the SYSLOGs of Network Devices.

 

-epm access-control open or access-session acl default passthrough

Not required - legacy troubleshooting thing for very early ISE releases.

 

-device classifier

Nope - You only need the IOS Device-Sensor these days.  IOS Device Classifier is a handy mechanism to decode the MAC OUI Prefixes into something more human readable. But it's not needed for NAC or for ISE.

 

There is an old  thread that explains some of the history too.

babalao
Spotlight
Spotlight

Hello,

thanks for the reply.

Is there a current switch config guide for best practices by Cisco?

Thank you.