just an FYI, i installed a new MS225 and blocked its MAC from ISE to replicate that ISE not responding, i had one machine with the applied access polices applied connected to the switch, and once the machine could not authenticate with ISE, the laptop had access to the internet and that's what we wanted. the VLAN 500 is defined in ISE, and since the MS is blocked, the 500 Vlan policy no longer applies.
... View more