<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 'secondary' vlan names in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322689#M110792</link>
    <description>&lt;P&gt;I am planning wired ISE for large university network where authenticated users will be assigned to a default data vlan by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few departments across the university that will require thier own vlans, usually in specific locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;'medical' vlan name is configured on access switches in a medical building, so any users in the medical group will be placed in a medical vlan on successful authentication, so they can access sensitive information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, If those users go to other locations, where 'medical' is not configured on the access switches they will get no network access at all.&lt;/P&gt;&lt;P&gt;I would like ISE to offer a 'secondary' option of the 'default data' vlan, so the authenticated user can still access core college resources+www wherever they are, even if they are not able to access specific 'medical' resources.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:57:44 GMT</pubDate>
    <dc:creator>mamckenn</dc:creator>
    <dc:date>2019-03-11T03:57:44Z</dc:date>
    <item>
      <title>'secondary' vlan names in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322689#M110792</link>
      <description>&lt;P&gt;I am planning wired ISE for large university network where authenticated users will be assigned to a default data vlan by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few departments across the university that will require thier own vlans, usually in specific locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;'medical' vlan name is configured on access switches in a medical building, so any users in the medical group will be placed in a medical vlan on successful authentication, so they can access sensitive information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, If those users go to other locations, where 'medical' is not configured on the access switches they will get no network access at all.&lt;/P&gt;&lt;P&gt;I would like ISE to offer a 'secondary' option of the 'default data' vlan, so the authenticated user can still access core college resources+www wherever they are, even if they are not able to access specific 'medical' resources.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322689#M110792</guid>
      <dc:creator>mamckenn</dc:creator>
      <dc:date>2019-03-11T03:57:44Z</dc:date>
    </item>
    <item>
      <title>'secondary' vlan names in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322690#M110794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P dir="ltr" style="font-size: 28px; font-family: sans-serif; left: 67.2px; top: 98.6399px; transform: scale(0.875025, 1); transform-origin: 0% 0% 0px;"&gt;Define VLANs Based on Enforcement States&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 144.96px; transform: scale(1.06336, 1); transform-origin: 0% 0% 0px;"&gt;Use the following command lines to define the VLAN names, numbers, and SVIs based on known&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 160.96px; transform: scale(1.05647, 1); transform-origin: 0% 0% 0px;"&gt;enforcement states in your network. Create the re&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 467.68px; top: 160.96px; transform: scale(1.05811, 1); transform-origin: 0% 0% 0px;"&gt;spective VLAN interfaces to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 630.64px; top: 160.96px; transform: scale(1.04547, 1); transform-origin: 0% 0% 0px;"&gt;enable routing between&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 176.959px; transform: scale(1.05503, 1); transform-origin: 0% 0% 0px;"&gt;networks. This can be especially helpful to handle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 472.401px; top: 176.959px; transform: scale(1.05815, 1); transform-origin: 0% 0% 0px;"&gt;multiple sources of traffic passing over the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 192.959px; transform: scale(1.05097, 1); transform-origin: 0% 0% 0px;"&gt;network segments—traffic from both PCs and the IP phone through which the PC is connected to the&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 208.959px; transform: scale(1.09758, 1); transform-origin: 0% 0% 0px;"&gt;network, for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 12px; font-family: sans-serif; left: 146.4px; top: 256.4px; transform: scale(0.914215, 1); transform-origin: 0% 0% 0px;"&gt;Note&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 255.12px; transform: scale(1.05597, 1); transform-origin: 0% 0% 0px;"&gt;The first IP helper goes to the DHCP server and the se&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 491.76px; top: 255.12px; transform: scale(1.04894, 1); transform-origin: 0% 0% 0px;"&gt;cond IP helper sends a copy of the DHCP request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 13.28px; font-family: serif; left: 192px; top: 271.12px; transform: scale(1.06049, 1); transform-origin: 0% 0% 0px;"&gt;to the inline posture node for profiling.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 306.64px; transform: scale(0.91428, 1); transform-origin: 0% 0% 0px;"&gt;vlan &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 230.4px; top: 306.64px; transform: scale(0.913244, 1); transform-origin: 0% 0% 0px;"&gt;VLAN_number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 300.72px; top: 306.64px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 320px; transform: scale(0.91333, 1); transform-origin: 0% 0% 0px;"&gt;name ACCESS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 333.279px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 346.639px; transform: scale(0.91428, 1); transform-origin: 0% 0% 0px;"&gt;vlan &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 230.4px; top: 346.639px; transform: scale(0.913244, 1); transform-origin: 0% 0% 0px;"&gt;VLAN_number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 300.72px; top: 346.639px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 359.999px; transform: scale(0.913244, 1); transform-origin: 0% 0% 0px;"&gt;name VOICE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 373.278px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 386.638px; transform: scale(0.913244, 1); transform-origin: 0% 0% 0px;"&gt;interface &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 262.32px; top: 386.638px; transform: scale(0.91428, 1); transform-origin: 0% 0% 0px;"&gt;VLAN_number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 332.719px; top: 386.638px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 191.999px; top: 399.997px; transform: scale(0.91368, 1); transform-origin: 0% 0% 0px;"&gt;description ACCESS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 191.999px; top: 413.277px; transform: scale(0.913945, 1); transform-origin: 0% 0% 0px;"&gt;ip address 10.1.2.3 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 191.999px; top: 426.637px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;ip helper-address &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 319.919px; top: 426.637px; transform: scale(0.913762, 1); transform-origin: 0% 0% 0px;"&gt;DHCP_Server_IP_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 460.64px; top: 426.637px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 439.996px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;ip helper-address &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 319.92px; top: 439.996px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;Cisco_ISE_IP_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 447.841px; top: 439.996px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192.001px; top: 453.276px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192.001px; top: 466.636px; transform: scale(0.913244, 1); transform-origin: 0% 0% 0px;"&gt;interface &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 262.321px; top: 466.636px; transform: scale(0.91428, 1); transform-origin: 0% 0% 0px;"&gt;VLAN_number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 332.72px; top: 466.636px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 479.995px; transform: scale(0.913647, 1); transform-origin: 0% 0% 0px;"&gt;description VOICE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 493.275px; transform: scale(0.913945, 1); transform-origin: 0% 0% 0px;"&gt;ip address 10.2.3.4 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192px; top: 506.635px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;ip helper-address &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 319.92px; top: 506.635px; transform: scale(0.913762, 1); transform-origin: 0% 0% 0px;"&gt;DHCP_Server_IP_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 460.641px; top: 506.635px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 192.001px; top: 519.994px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;ip helper-address &amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 319.922px; top: 519.994px; transform: scale(0.91371, 1); transform-origin: 0% 0% 0px;"&gt;Cisco_ISE_IP_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr" style="font-size: 10.64px; font-family: monospace; left: 447.842px; top: 519.994px; transform: scale(0.912, 1); transform-origin: 0% 0% 0px;"&gt;&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Oct 2013 00:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322690#M110794</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-26T00:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: 'secondary' vlan names in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322691#M110796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe you could use Network Device Groups here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You create a NDG for 'medical' switches and the use that in your authorization policy.&lt;/P&gt;&lt;P&gt;IF (device=medical) AND (user = AD group XX) THEN (vlan 'medical')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if they dont mach that one they get a 'normal' on the next line.&lt;/P&gt;&lt;P&gt;IF&amp;nbsp; (any) AND (user = AD group XX) THEN (vlan 'normal')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use Policy Sets you can use diffrent policies for diffrent NDGs, might be easier if the policy gets large. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Oct 2013 09:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322691#M110796</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2013-10-26T09:54:20Z</dc:date>
    </item>
    <item>
      <title>'secondary' vlan names in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322692#M110797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+5 for michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you are using ISE 1.2 you have the ability to run policy sets. In each policy set you can break apart the sets based on location and then use your conditions to map to the authorization profile you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Oct 2013 07:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secondary-vlan-names-in-ise/m-p/2322692#M110797</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-10-27T07:07:23Z</dc:date>
    </item>
  </channel>
</rss>

