<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and VLAN assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342376#M103980</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Bike, Ravi,&lt;/P&gt;&lt;P&gt;Thank you both for the quick and great responses. Very valuable info.&lt;/P&gt;&lt;P&gt;I still have reluctance to implement things this way for more of a human rather than technical reason.&lt;/P&gt;&lt;P&gt;The customer is proposing they will have two MAC adddress lists, one for "trusted" corporate devices and one for "not so trusted" devices.&amp;nbsp; I see that being the weak link in the policy more than anything.&lt;/P&gt;&lt;P&gt;Again, thanks for the comments.&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Aug 2013 19:42:01 GMT</pubDate>
    <dc:creator>andrew.chappelle</dc:creator>
    <dc:date>2013-08-01T19:42:01Z</dc:date>
    <item>
      <title>ISE and VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342373#M103882</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can ISE place a connection into a VLAN based on MAC address? (Both wired and wireless).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;•- Users are wired and wireless, distributed around the campus. There are a dozen VLANs, one per closet, that are dedicated to users.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•- Laptops are bad at least in the mind of the customer. So a laptop (wired or wireless) leaves the campus and returns; possibly with the plague.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•- For each closet we want to create a “restricted” VLAN for bad laptops; and a “good” VLAN for desktop users.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•- We have a list of all the laptop MAC addresses; and a list of all the desktop MAC addresses.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•- Can we see the laptop MAC address logging in; and place that laptop into a relevant “restricted” VLAN, based on location?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•- Likewise can we see all the other MAC addresses and place the user into a relevant “good” VLAN, based on location?&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your comments!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342373#M103882</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2019-03-11T03:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342374#M103933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you create a rule per location then yes.&lt;BR /&gt;If a rule per location is not suitable then you could use one rule, which dumps them in to a vlan based on the vlan name, but then you obviously need separate vtp domains per location.&lt;BR /&gt;Careful when you dynamically allocate vlans that you may need to change to port bounce for COA to allow DHCP to do its thing, which is a global setting up until version 1.2.&lt;BR /&gt;Version 1.2 also has other flexibilities which might be useful to you (nested rules so I believe you may be able to have one rule with multiple profiles based on location), but I've not played with them too much yet.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jul 2013 23:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342374#M103933</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2013-07-31T23:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342375#M103964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to create location based rule in ISE&amp;nbsp; then it is possible. ISE 1.2 is providing lots of feature on location basis. Please check the release notes of ISE 1.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 02:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342375#M103964</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-08-01T02:09:15Z</dc:date>
    </item>
    <item>
      <title>ISE and VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342376#M103980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Bike, Ravi,&lt;/P&gt;&lt;P&gt;Thank you both for the quick and great responses. Very valuable info.&lt;/P&gt;&lt;P&gt;I still have reluctance to implement things this way for more of a human rather than technical reason.&lt;/P&gt;&lt;P&gt;The customer is proposing they will have two MAC adddress lists, one for "trusted" corporate devices and one for "not so trusted" devices.&amp;nbsp; I see that being the weak link in the policy more than anything.&lt;/P&gt;&lt;P&gt;Again, thanks for the comments.&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 19:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/2342376#M103980</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2013-08-01T19:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3673050#M104005</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a similar same. I configured mab authentication on 3750 cisco switch (Version 12.2(44r)SE3) for dynamic assigned vlan but when I pluged my laptop to switch port, my laptop cannot assign to desired vlan. Please take a look configured in my attached.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 12:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3673050#M104005</guid>
      <dc:creator>vantoanbcvt.09081</dc:creator>
      <dc:date>2018-07-24T12:05:59Z</dc:date>
    </item>
  </channel>
</rss>

