iDentiFi 802.1x using NAC. deny all devices that are non-domain
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-16-2016 03:39 AM
how to configure 802.1x in NAC to deny all devices that are not member of the domain?
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-28-2016 01:20 PM
Thanks Ronald!
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-16-2016 05:06 AM
Here a example if you want to create a explicit rule for NOT in AD group X.
A user with..
- authentication 802.1X PEAP
- NOT in AD group Team (checkmark invert on the right)
- end system group WLAN_Team
- Location Zone Home & SSID Secure Access
will get a Deny Access Rule
So you set the "invert" to reverse the rule = NOT in this AD group
A user with..
- authentication 802.1X PEAP
- NOT in AD group Team (checkmark invert on the right)
- end system group WLAN_Team
- Location Zone Home & SSID Secure Access
will get a Deny Access Rule
So you set the "invert" to reverse the rule = NOT in this AD group
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎06-16-2016 04:12 AM
Just setup your NAC rule to do it. If the computer isn't in AD, let it fall through to a reject policy. Look at the documentation for filtering on computer name in domain. It's fairly easy.
