Cisco Wired Layer 2 Integration(IE2000)

Note – In this example, a Cisco IE-2000-4TS-B configuration is provided. However, any Cisco IE Layer 2 switch supporting the following features are eligible for integration:

  • RADIUS Authentication/Accounting
  • 802.1X
  • MAC Authentication Bypass (MAB)
  • RADIUS Change of Authorization (CoA)
  • Cisco-AVPair “url-redirect”
  • Cisco-AVPair “url-redirect-acl”

Note – In this example the NAC RADIUS Server / Policy Server is 10.10.10.10 (replace this IP with the IP of your NAC system)

Note – Replace the VLAN number on the example port configuration with the desired default VLAN for the port.

Note – The “radius-server vsa send authentication” command is enabled by default and auto-generated on some IOS

versions. If the command does not show up in a sh run, “sh run all” can be used to verify that it is configured on the

switch.

Layer 3 DHCP prerequisites

Bash
Copy

Layer 2 Switch Configuration

Bash
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard