Skip to content

Cisco ISE

Configure Cisco Identity Services Engine (ISE) to admit the RTA appliance via MAC Authentication Bypass (MAB), place it in an authorized VLAN with outbound internet access, and exempt it from posture checks.

Note

For the full explanation of why NAC blocks the appliance and the three-step fix (MAB allowlist → authorized VLAN → posture bypass), see Network Access Control. For upstream connectivity requirements (the endpoint and port the appliance must reach), see Connectivity troubleshooting.

Choose how to apply the fix

  • GUI (ISE admin portal)

    Create the endpoint identity group, MAB authorization rule, and posture bypass step by step in the ISE admin portal.

  • CLI (ERS API)

    Script the endpoint allowlist (identity group plus MAC registration) with curl against the ERS REST API; the policy steps stay in the portal.

  • AI assistant (LLM)

    A copy-paste prompt that has your AI assistant walk the ISE configuration with you, pausing for your confirmation at each step.