See your real 802.1X coverage, port by port
ISE knows who connected. The inventory knows on which port, on which switch, in which building. NacTrack joins the two and the gap becomes a number.
What the integration exposes
Live sessions
Sessions in progress, with the split between 802.1X and MAB. That is the real coverage rate, not the project's.
Profiled endpoints
What ISE identified: endpoint type, vendor, group. Useful for understanding what is genuinely plugged in.
Network access devices
The devices declared in ISE, compared against the real inventory. The gaps show immediately.
TACACS administration
Profiles and command sets: who can administer what, and with which commands allowed.
TrustSec matrix
Group tags, group ACLs and the egress matrix: the segmentation policy, readable at a glance.
Configured 802.1X ports
On the switch side, control mode, MAB and host mode per port. The gap between configured and active becomes measurable.
The same ports, counted three times
Each source measures something narrower than the one before. That is why the three figures never coincide, and the gap is the part you want.
- Announcedthe ports in the project's scope
- Carried by the configurationdot1x actually present, in the right mode
- Confirmed by sessions802.1X authentication, no fallback to MAB
The proportions drawn illustrate the shape of the argument, they are not measurements: on your estate it is your own figures that appear, port by port and site by site.
The gap between the NAC on paper and the NAC in place
Three measurements of the same population of ports, in that order.
- Rate announced: the sites deployed and the switches in scope.
- Real rate, source 1: the access ports whose configuration actually carries dot1x, with the right mode and MAB where it belongs.
- Real rate, source 2: the sessions that authenticate over 802.1X rather than falling back to MAB.
- The gap comes from everyday work: a port flipped in a hurry to fix a printer, a room repatched on a Saturday, a device replaced with a configuration recovered from elsewhere.
- Joining the two sources makes the gap measurable, port by port and site by site.
- On IOS and IOS XE, dot1x placed in a policy template does not appear in the interface configuration. The parser follows the template rather than concluding it is absent.

This module is in the lab
- Every one of its pages carries the notice in the product, and you will see it from the demonstration onwards.
- It is open to customers who want to use it and shape it with us. What is described here is what works today, not an intention.
- The module catalogue says which other modules are in the same position.
