radius server vsa send authentication is enabled by default on IOS 15.X and later versions. To configure a switch to accept downloadable ACLs from a Cisco ISE server, the following two commands are required: ip device tracking: This command enables the switch to track IP device information, which is needed for the ISE server to provide dynamic access policies based on a device's IP address. dot1x system-auth-control: This command enables 802.1X authentication on the switch and allows the switch to forward authentication requests to the ISE server.