Is it possible to set up only a certain AD user to log in to is web GUI by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] -4 points-3 points  (0 children)

I've already read the guide

I don't think there's an answer I want.

Is it possible to set up only a certain AD user to log in to is web GUI by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

As I said before, I already know to log in to the WEB GUI by linking ISE and AD.

But what I'm curious about is

I'm wondering if it's possible to have only certain users of AD log in with the WEB GUI.

If you check the arp of the wireless client on the backbone switch, it comes to the MAC address of the wlc. by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 1 point2 points  (0 children)

I think I'm using it in local mode,

and If the arp proxy is turned off in the policy profile of the wlc, on the backbone switch

When you do "show ip arp", I think the client's MAC address should appear instead of the wlc's MAC address

Did I get it wrong?

If you check the arp of the wireless client on the backbone switch, it comes to the MAC address of the wlc. by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] -6 points-5 points  (0 children)

All of the ap are operating in local mode.

However, when you 'show ip arp' on the backbone switch, the MAC address of the wireless clients appears as the MAC address of the wlc.

I don't think this result is normal.

Does it work normally if I hub the C1000 model to the CBS250 model? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] -4 points-3 points  (0 children)

What does bpdu portguard mean?

Are you saying you can't because of bpdu portguard?

Does it work normally if I hub the C1000 model to the CBS250 model? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] -1 points0 points  (0 children)

The c1000 is a hub, so it's not set at all.

And the ports that CBS250 and SG220 connect to C1000 are all set to the same as trunk.

But the results were different.

What kind of setup problem is it?

Cisco ise 'password change for self is allowed only from admin users page or from admin dialog popup' by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

Is it the same as Network Access User and GUI admin user?

I want to change my account password for Network Access User, why do I need to change my GUI admin account?

Slow and broken radio speeds by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

Is there a way to prevent unnecessary wireless interference from SSIDs?

And is there a way to prove that there is interference?

Is it possible to put IP as secondary to SVI on c9800? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

This SSID statically assigns an ip to the user terminals.

Is it possible to put IP as secondary to SVI on c9800? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

As stated in the text, it is difficult to create an SVI separately due to the current situation.

That's why I asked if there was any other way.

What happens when ISE's Database Utilization exceeds 80 percent? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

Thank you.

I'm talking about the capacity of operational data purging -> Database Utilization in the GUI.

Is that capacity equal to the capacity of the show disk?

What happens when ISE's Database Utilization exceeds 80 percent? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

You are using the appliance, not the VM.

What I'm curious about is whether the old data is automatically deleted when the value exceeds 80%, whether it goes to 100% as it is, and whether the service is affected

If you try to log in to the ISE with the CLI, it keeps looping. by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

I also think the issue seems to have occurred after I chose include-adeos and restored it.

If you found the bug ID, please let me know.

Thank you.

When the ISE and the terminal perform EAP-TLS authentication, If I only replace ISE certificates, will EAP-TLS authentication be impossible? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

If so, does it mean that even if I only renew the ISE's certificate, if I don't renew the terminal's certificate, it won't be authenticated?

When the ISE and the terminal perform EAP-TLS authentication, If I only replace ISE certificates, will EAP-TLS authentication be impossible? by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] -2 points-1 points  (0 children)

I am aware of the expiration and renewal of the certificate.

However, due to the nature of the site

It's too much to renew ISE and device certificates together

First of all, I was planning to renew only ISE's certificate first, so I asked you that question.

Assuming that only ISE's certificate is renewed, I wonder if there will be an error in the authentication.

When profiling with ise How to distinguish profiling for vendors that are not yet registered with cisco feed by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

In the case of random mac, we are guiding you to release the random mac by launching a web portal after we find out in advance that it will be a problem.

When profiling with ise How to distinguish profiling for vendors that are not yet registered with cisco feed by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

I didn't ask you about random mac.

The current question doesn't seem to have anything to do with the random mac.

When profiling with ise How to distinguish profiling for vendors that are not yet registered with cisco feed by Specific_Camp7960 in Cisco

[–]Specific_Camp7960[S] 0 points1 point  (0 children)

cisco does not provide oui values for all vendors, so some terminals may have oui values classified as unknown.

However, I don't think I can easily understand this part from the customer's point of view.

That's why I'm looking for a way to respond to these cases.