Saturday, February 27, 2021

Cisco Identity Based Firewall Access - Issues

Hello,

I’ve recently setup identity based access on our Cisco firewalls using Cisco ISE.

I have five locations that this is setup for. Rules are in place for wired and wireless networks that require identity to work.

My problem is that when someone swaps from either wired or wireless, they get a new IP address on a different subnet and thus the identity rules no longer work.

I’m really struggling to find a solution to this. Is there anyway that I can resolve this without asking people to lock and unlock their machine? I’m not sure if there’s any AnyConnect modules available that can assist with this?

TIA.



No comments:

Post a Comment