Phase 4: Network Access Policy

Now that our infrastructure is secure and our identities are verified via certificates, we can define the rules that govern who gets on the network and what they can do.

Configuring MAB (MAC Authentication Bypass)

MAB is used for devices that do not support 802.1X (e.g., printers, cameras, some IoT devices). ISE identifies these devices based on their MAC address.

  1. Identity Source: Ensure the MAC addresses of these devices are stored in an identity store (like an Internal Endpoints database).
  2. Policy Creation: In your Policy Set, create an Authentication Policy that checks for the presence of a MAC address.
  3. Security Note: MAB is less secure than 802.1X as MAC addresses can be easily spoofed. Use it sparingly and combine it with profiling for better security.

Configuring 802.1X (DOT1X)

802.1X is the gold standard for secure network access, providing port-based authentication using strong credentials or certificates.

  1. Client Configuration: Ensure end-user devices (laptops, phones) are configured with a supplicant (e.g., Windows Native Supplicant) to provide credentials.
  2. Network Device Setup: Configure your switches or WLCs to act as RADIUS clients and point them toward your ISE nodes.
  3. ISE Configuration: Create Authentication Policies that require EAP-TLS (for certificate-based) or PEAP (for username/password-based) authentication.

Creating Authorization Profiles

An Authorization Profile defines what a user or device is allowed to do once they are authenticated. It is the "result" of a successful login.

Commonly configured elements in an Authorization Profile include:

Example: A "Printer_Access" profile might simply assign the "Printer_VLAN" and apply a dACL that only allows printing traffic.

Building Policy Sets

A Policy Set is a container that bundles together Authentication and Authorization logic for a specific type of access (e.g., "Wired Access" or "Wireless Access").

1. Authentication Policy (The "Who")

The Authentication Policy determines how we verify identity. This is where you use the Certificate Authentication Profiles (CAPs) created in Phase 3.

2. Authorization Rules (The "How")

Once identity is proven, the Authorization Rule determines what permissions to grant. This is where you map conditions to your Authorization Profiles.

The Policy Set Evaluation Process

When a request hits ISE, it follows this logic:

  1. Match Policy Set: ISE looks for a Policy Set that matches the incoming request (based on device type, location, etc.).
  2. Authentication: Inside that set, it runs the Authentication Policy to verify who the requester is.
  3. Authorization: If authentication succeeds, it runs the Authorization Rules to decide what they can do.
  4. Result: The chosen Authorization Profile is sent back to the network device to enforce the access.