Skip to content
CONFIGLANE

Security & network access / NAC & 802.1X with Cisco ISE

NAC and 802.1X.Network access backed by verifiable identity.

A port is not an identity. We design Cisco ISE, certificates, network devices and endpoints as one access service, with a pilot, clear exception paths and an operating model that still works after the project.

Scope of service

What you receive.

This service fits new NAC programmes, replacement of shared credentials, extension from wireless to wired ports, ISE migration and unstable authentication workflows. We begin with identities, client classes and operational scenarios. Policies follow those requirements rather than an ambition to create as many technical rules as possible.

An understandable access model

Employees, managed endpoints, guests, printers, phones, technical systems and exceptions receive traceable roles. The choice between certificates, user identity and restricted device recognition is justified for each class.

PKI, clients and network in one plan

Certificate profiles, enrolment, supplicant configuration, switches, wireless, RADIUS and ISE nodes are considered together. Endpoint, PKI and network ownership is clear before the pilot.

Policies introduced through a safe pilot

Authentication, authorisation, profiling and failure cases are first observed or validated in bounded areas. Controlled exceptions have a purpose, owner and expiry date.

Operations and troubleshooting

Runbooks, monitoring, certificate deadlines, platform lifecycle and common failure patterns are handed over. Operations can trace an access decision from the client through to the applied policy.

The delivery path

Three controlled steps.

  1. 01

    Structure identities and device classes

    Map users, endpoints, certificate paths, network devices and current exceptions. Define target roles and accountable owners.

  2. 02

    Begin with an observable pilot

    Integrate ISE, RADIUS, PKI and selected ports or SSIDs. Observe results, exercise failures and refine policy incrementally.

  3. 03

    Expand enforcement and operations

    Move areas after acceptance, control exceptions and hand monitoring, backup, lifecycle and support paths into regular operations.

What we agree before starting

NAC is not a standalone network appliance. Endpoint configuration, PKI, directories and operational ownership are prerequisites. MAC-based recognition may be necessary for limited device classes, but it is not an equivalent identity signal. Licensing, 24/7 service and client rollout are agreed separately.

Good to know

Your questions. Clear answers.

Does every device need to support certificates?

No, but managed devices benefit from a strong identity signal that can be automated. We design constrained alternatives and compensating controls for devices without a suitable supplicant. Those exceptions are not presented as equivalent.

Can 802.1X be introduced without immediately blocking devices?

Yes. A monitor or low-impact approach can expose real devices and failures before broad enforcement. The exact path depends on switch capabilities, clients, the security objective and the available fallback.

Who operates certificates and ISE afterwards?

That is established before rollout. Certificate lifecycle, endpoint configuration, policy, platform maintenance and incident diagnosis may sit with different teams. We document handoffs and can provide agreed ISE operational services.

Let’s discuss your requirements

A few details are enough to begin.

You do not need a finished design. We establish the need, boundaries and a dependable next step.

Discuss NAC and Cisco ISE

Helpful for the first conversation

  • User, device and exception groups
  • PKI, endpoint management and directory services
  • Switch, wireless and ISE estate
  • Pilot areas, operating periods and fallback requirements

Please do not submit passwords, API keys or confidential network plans through the form.

Explore the technical detail

Introducing wired 802.1X without a widespread outage

Technical background: Cisco: Configure EAP-TLS Authentication with ISE

More Security & network access services