Meraki MS switches and ISE posture

Solved
charles07
Getting noticed

Meraki MS switches and ISE posture

Has anyone done Cisco ISE Posture for endpoint devices like laptop, desktop etc with Meraki MS switches in the network. Posture conditions are Domain joined, AV etc.

 

Should 802.1x be configured on switches for this? It's ok if nay system is connected to nay port in the switch. Once posture conditions are met they should be permitted to the network.

1 Accepted Solution
charles07
Getting noticed

i did the setup successfully referring different docs. In below link i have outlined the steps followed.

https://community.meraki.com/t5/Switching/Meraki-MS-Wired-Posture-with-Cisco-ISE/td-p/220229

View solution in original post

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

It's fully supported

Please see our compatibility matrix

 

https://communities.cisco.com/docs/DOC-68192?mobileredirect=true

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
charles07
Getting noticed

Thank you,

should 802.1x configured on switches for the basic ISE posture to work.
are there any configuration document for Meraki switch config for ISE posture.

alemabrahao
Kind of a big deal
Kind of a big deal

In this same document there is a guide.

 

https://community.cisco.com/t5/security-knowledge-base/how-to-integrate-meraki-networks-with-ise/ta-...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
GIdenJoe
Kind of a big deal
Kind of a big deal

Since the posture check is on the endpoint itself ISE will decide what to send to the switch for network access.  There is no other input needed than what the endpoint agent provides.  So the switch will not need to use any special features for it to work.

charles07
Getting noticed

Thank you @GIdenJoe when a user first time connects to local network, how can they redirected to the ISE portal to download and install ISE agent. Whenever a new user connects he/she needs to be redirected to download and install ISE posture agent, once posture is successful they'll be permitted to the network.
Thanks in advance.

charles07
Getting noticed

Any solution on this???

 

charles07
Getting noticed

i did the setup successfully referring different docs. In below link i have outlined the steps followed.

https://community.meraki.com/t5/Switching/Meraki-MS-Wired-Posture-with-Cisco-ISE/td-p/220229

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels