Re: [OSL | CCIE_Security] Authorization Policies on ISE

2013-10-12 Thread Tarik Admani
Mike, Can you check and see if ip device-tracking is enabled on the switch? It seems as if the switch is not learning the ip address of the client and therefore provision the source host of the dacl. Thanks, Tarik Admani ___ For more information

Re: [OSL | CCIE_Security] Wireless Dot1x

2013-10-12 Thread Tarik Admani
Mike, Where are you saving the profile to? Also my experiences with NAM I typically just modify the current running system config file and then hit the repair button, sometimes I even restore to bouncing the nam service on the client also. Thanks, tArik

Re: [OSL | CCIE_Security] Wireless Dot1x

2013-10-12 Thread Mike Rojas
Tarik; Thank you for your attention to this issue. So I brought a wireless CCIE to help me a bit and we found out the issue. PEAP was failing because I had a Typo on the authorization ACL on the ISE. Once we corrected the typo PEAP worked and I was able to see it working. Just CWA and It