In ISE, switches are referred to as a Network Access Device (NAD). Other NAD devices include wireless LAN controllers and VPN concentrators. NADs are responsible for enforcing ISE policies on devices connecting to the network with MAB authentication via RADIUS, as well as authorization of remote device administration over SSH via TACACS+.
Before a switch will act as a NAD, it needs to be added to ISE as an object and configured for use as both a RADIUS and TACACS server with a shared key.
To add a new switch to act as a NAD in ISE:
- Navigate to Administration > Network Resources > Network Devices.
- Click the + Add button.
- Configure the following attribute fields:
- Name: Type in the hostname of the switch.
- IP Address: Type the management IP address of the switch.
- Location: Click the drop-down and select Location.
- IPSEC: Click the drop-down and select Is IPSEC Device.
- Device Type: Click the drop-down and select Device-Type.
- Click the checkbox next to RADIUS Authentication Settings and configure the Shared Secret.
- Click the checkbox next to TACACS Authentication Settings and configure the Shared Secret.
- Click the Submit button to complete the configuration.
To edit the configuration of an existing device:
- Navigate to Administration > Network Resources > Network Devices.
- Click the checkbox next to the device to configure.
Tip: You can click the Show: drop down box and select Quick Filter option to search for a specific device using the Name or IP column. - Click the Edit button.