Cisco Catalyst C9200 IOS XE integration
NAC Cisco Layer 2 Switch Configuration Example:
Note – In this example, a Cisco Catalyst C9200 IOS XE configuration is provided. Cisco Catalyst 9200 running IOS XE 17.6.1 or later are supported for centrally switched traffic. However, any Cisco C9K switch supporting the following features are eligible for integration:
RADIUS Authentication/Accounting
802.1X
MAC Authentication Bypass (MAB)
RADIUS Change of Authorization (CoA)
Cisco-AVPair “url-redirect”
Cisco-AVPair “url-redirect-acl”
Note – In this example the NAC RADIUS Server / Policy Server is 10.10.10.10 (replace this IP with the IP of your NAC system)
Note – Replace the VLAN number on the example port configuration with the desired default VLAN for the port.
IBNS 2.0 Policy and Interface Configuration
Service Template:
Class map:
Policy map:
On the 3 following configurations if the RADIUS server is down then we will apply CRITICAL_AUTH_VLAN, DEFAULT_CRITICAL_VOICE_TEMPLATE and CRITICAL-ACCESS service template. If the RADIUS server goes up then it reinitializes the authentication if the port is in IN_CRITICAL_VLAN.
for 802.1X with MAC Authentication fallback:
for MAC Authentication only:
for 802.1X only:
Interface Template (802.1X MAC Authentication):
Interface Template (MAC Authentication):
Interface Template (802.1X):
Apply the new policy-map to the Test interface
Troubleshooting command:
When you use Port Templates, use the command "show derived-config" to see the actual (total) configuration on an interface after the Template has been applied to it.