Solved
NAC - wired switchport default VLANs for various use cases
I'm looking for some best practices for setting the 'starting default' wired switchport vlans when deploying NAC.
What is reccommended for each of these cases ?
a) dead end VLAN with zero access ?
b) guest network VLAN that denies access to any corporate resources ?
c) a isolation vlan with a captive portal ?
1) Switchports configured for 802.1x used by corporate computer access. I have a NAC policy to identify 802.1x/TLS cert auth and change the port to a 'prod' vlan.
2) Switchports dedicated to IOT devices. Device profiling will trigger a access policy to put these devices in the right vlan like camera, door badge systems, printers, etc.
3) Switchports dedicated for byod devices. Access policy will force the users into a registration portal w/ dissolveable agent.
Thanks for any insight.
