cancel
Showing results for 
Search instead for 
Did you mean: 

Configuration of IC4000 with 802.1x

SOLVED
Kamran_
Contributor

Configuration of IC4000 with 802.1x

Dear all

My scenario is that i have one IC4000 one ISG-2000 and one 802.1x compatible switch in my testlab, servers are Domain controller with CA,DNS,DHCP,IAS. i want to deploy IC4000 with ISG-2000(as Enforcer) and wanna use 802.1x funtionalities like no ip assignment befoce checking computer's certificate etc...i have configure IC to link with ISG-2000(Enforcer), i made VLANs on switch and mapped these VLANs to ISG-2000(Enforcer) untrust interface by creating subinterfaces. i need to check if there is no Antivirus updates on a system it should be assign a Remediation VLAN...how it will be possible .?? what configuration i need to do on these three devices IC, Firewall(ISG-2000) and switch....i wanna use IC's radius instance not IAS.

Plz give me urgent and detaild reply

Thanks to ALL

Raja M Kamran

System Administrator (Suparco, Pakistan)

1 ACCEPTED SOLUTION

Accepted Solutions
ManojReddy_
Contributor

Re: Configuration of IC4000 with 802.1x

Hi,

only the devices acting as 802.1X authenticators are requried to be added as RADIUS clients in IC.

So, if you are doing 802.1x only using switches(FW's can also do 802.1x), just add the switches as radius clients in IC, you don't need to add Firewall as radius client.

Dynamic VLANs: instead of configuring VLAN statically on switch port, many of the switches can get VLAN ID of the port from a RADIUS server after completing 802.1x authentication.

when you are creating Radius Attribute policies on IC and mentioning VLAN-ID in the policy, you are using Dynamic VLANs.

thanks

Manoj

View solution in original post

4 REPLIES 4
ManojReddy_
Contributor

Re: Configuration of IC4000 with 802.1x

Hi Kamran,

here are high level steps for your config:

On IC do the following:

1)Create an Active Directory auth server instance on IC and give details of your Domain controller

2)Use this Active Directory auth server as Auth server for your realm (you can use existing Users realm or create a new one)

2)Create two roles on IC. one for users who pass your requirements(like having antivirus updates installed..etc) and one for users who fail your security policy requirements.

3)Create a role mapping rule under realm to map all users to both these roles(I assume this is a test setup and you are not doing any AD group lookups)

4)Create a Host Checker policy which will check for Antivirus signature updates on users PC(or for any other requirement you have)

5)apply this Host Checker policy to one of the roles you created

6)create a location group which uses the default sign-in url (you can use your own sign-in url as well)

7)create a radius client and give details of your 802.1x switch (like IP of switch and make of the switch and a shared secret) and attach it to the location group you configured in step-7

8)create two radius attribute policies on IC. apply one policy(top policy in the list) to role for which you attached Host Checker policy and give a vlan ID (in which you want to put your HC passed users in). apply second radius attribute policy to second role which doesn't need HC and give the VLAN id of your remediation VLAN

on the switch:

1)configure the IC's IP Address as radius server IP and give shared sceret which you configured in step-7 above

2)enable 802.1x on the switch port

on the PC:

1)install the OAC

2)create a profile in OAC and give the details of username/password

3)Add the wired adapter for 802.1x in OAC and 'connect'

I tried to cover all the stuff you asked for at a high level.

let us know how you are going to use ISG-2000 in your test network.

also let us know if you want more help.

Thanks

Manoj

Kamran_
Contributor

Re: Configuration of IC4000 with 802.1x

Thanks man for quick reply, i m doing steps that u mentioned, let's see what happens???

Thanks again for ur help

keep it up

Take gr8care

Raja Kamran

Kamran_
Contributor

Re: Configuration of IC4000 with 802.1x

sir

one more thing i wanna know, only switches will be radius client (of IC4000) or Firewall should also be?? my question is both switches and firewall will be radius client of IC4000 or just one firewall / switch??

Further i wanna use dynamic vlans..??? any words abt dynamic vlans !!!

ManojReddy_
Contributor

Re: Configuration of IC4000 with 802.1x

Hi,

only the devices acting as 802.1X authenticators are requried to be added as RADIUS clients in IC.

So, if you are doing 802.1x only using switches(FW's can also do 802.1x), just add the switches as radius clients in IC, you don't need to add Firewall as radius client.

Dynamic VLANs: instead of configuring VLAN statically on switch port, many of the switches can get VLAN ID of the port from a RADIUS server after completing 802.1x authentication.

when you are creating Radius Attribute policies on IC and mentioning VLAN-ID in the policy, you are using Dynamic VLANs.

thanks

Manoj