Cisco ISE¶
Configure Cisco Identity Services Engine (ISE) to admit the RTA appliance via MAC Authentication Bypass (MAB), place it in an authorized VLAN with outbound internet access, and exempt it from posture checks.
Note
For the full explanation of why NAC blocks the appliance and the three-step fix (MAB allowlist → authorized VLAN → posture bypass), see Network Access Control. For upstream connectivity requirements (the endpoint and port the appliance must reach), see Connectivity troubleshooting.
Choose how to apply the fix¶
-
Create the endpoint identity group, MAB authorization rule, and posture bypass step by step in the ISE admin portal.
-
Script the endpoint allowlist (identity group plus MAC registration) with
curlagainst the ERS REST API; the policy steps stay in the portal. -
A copy-paste prompt that has your AI assistant walk the ISE configuration with you, pausing for your confirmation at each step.