Phase 4: Network Access Policy
Now that our infrastructure is secure and our identities are verified via certificates, we can define the rules that govern who gets on the network and what they can do.
Configuring MAB (MAC Authentication Bypass)
MAB is used for devices that do not support 802.1X (e.g., printers, cameras, some IoT devices). ISE identifies these devices based on their MAC address.
- Identity Source: Ensure the MAC addresses of these devices are stored in an identity store (like an Internal Endpoints database).
- Policy Creation: In your Policy Set, create an Authentication Policy that checks for the presence of a MAC address.
- Security Note: MAB is less secure than 802.1X as MAC addresses can be easily spoofed. Use it sparingly and combine it with profiling for better security.
Configuring 802.1X (DOT1X)
802.1X is the gold standard for secure network access, providing port-based authentication using strong credentials or certificates.
- Client Configuration: Ensure end-user devices (laptops, phones) are configured with a supplicant (e.g., Windows Native Supplicant) to provide credentials.
- Network Device Setup: Configure your switches or WLCs to act as RADIUS clients and point them toward your ISE nodes.
- ISE Configuration: Create Authentication Policies that require EAP-TLS (for certificate-based) or PEAP (for username/password-based) authentication.
Creating Authorization Profiles
An Authorization Profile defines what a user or device is allowed to do once they are authenticated. It is the "result" of a successful login.
Commonly configured elements in an Authorization Profile include:
- VLAN Assignment: Dynamically placing a user into a specific VLAN.
- Downloadable ACL (dACL): Applying a specific set of IP/Protocol filters to the switch port.
- SGT (Scalable Group Tag): Assigning a tag for Cisco TrustSec environments.
Example: A "Printer_Access" profile might simply assign the "Printer_VLAN" and apply a dACL that only allows printing traffic.
Building Policy Sets
A Policy Set is a container that bundles together Authentication and Authorization logic for a specific type of access (e.g., "Wired Access" or "Wireless Access").
1. Authentication Policy (The "Who")
The Authentication Policy determines how we verify identity. This is where you use the Certificate Authentication Profiles (CAPs) created in Phase 3.
- Rule Logic: "If the connection is using a certificate, use
CAP_Internal_CA to validate it."
2. Authorization Rules (The "How")
Once identity is proven, the Authorization Rule determines what permissions to grant. This is where you map conditions to your Authorization Profiles.
- Rule Logic: "If the user is in the 'Finance' group AND the device is 'Compliant', then apply the
Finance_Full_Access profile."
The Policy Set Evaluation Process
When a request hits ISE, it follows this logic:
- Match Policy Set: ISE looks for a Policy Set that matches the incoming request (based on device type, location, etc.).
- Authentication: Inside that set, it runs the Authentication Policy to verify who the requester is.
- Authorization: If authentication succeeds, it runs the Authorization Rules to decide what they can do.
- Result: The chosen Authorization Profile is sent back to the network device to enforce the access.