<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic Vlan Assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079108#M204675</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Neil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add to what Tarik said, I would also describe that can be used with whatever radius server you have.&lt;/P&gt;&lt;P&gt;in ISE (Tarik, correct me if I am wrong) the devices and getting profiled automatically depending on many attributes and the device can be distinguished if it is an ip phone, laptop, ipad...etc. and based on that the VLAN assignmed is applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With other radius servers you need to statically specify what VLANs should the users be put in. The VLAN assignment is being done based on username the user is using OR the mac address the device provides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two weeks ago I implemented the same scenario using cisco ACS 5.3 radius server where users have multiple AD users and some other devices (ip phones, network printers...etc) and the VLAN assignment happens based on the AD group or the type of the device.&lt;/P&gt;&lt;P&gt;I manually added the mac addresses of priners in a group, ip phones in different group..etc. and I configured the ACS to assign the VLAN based on that gorup. with ISE what I know is it detects the device type automatically (you have to configure a profile for device types though) and based on that it assigns a VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to notice one thing though, if you are configuring the switch for the dot1x authentication you need to add a configuraiton in the radius in order to tell the switch to use teh VOICE vlan (not DATA vlan) for the phones. Otherwise the phone will use DATA VLAN when authenticated and not the voice VLAN which makes only one device; the phone or the PC attached to it, to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use cisco switches, you need to return to cisco-av-pair attribute with value "&lt;STRONG style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif; text-align: justify;"&gt;device-traffic-class=voice&lt;/STRONG&gt;" to the phones when they authenticate. I used this with non-cisco phones and it works like a charm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if there is anything else you need to know about dynamic vlan assignment. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that was useful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Jan 2013 13:01:55 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2013-01-27T13:01:55Z</dc:date>
    <item>
      <title>Dynamic Vlan Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079106#M204577</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking for a means to secure interfaces configured in an admin vlan.&lt;/P&gt;&lt;P&gt;In an ideal world the interface would be configured with the admin vlan if the device is somehow identified (not necessarily authenticated). In the event that the device isn't identified it fails back to a standard device vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had a look at VMPS but understand that this is a dying feature and would be a poor idea to implement it. The alternative appears to be passing a vlan tag as a RADIUS attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd be keen to know if anybody can make any suggestions as to how I could implement this? Ideally it needs to be simple with fewer complexities to go wrong.&lt;/P&gt;&lt;P&gt;To add to this, devices are hanging off of IP phones which aren't Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neil&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079106#M204577</guid>
      <dc:creator />
      <dc:date>2019-03-11T02:59:22Z</dc:date>
    </item>
    <item>
      <title>Dynamic Vlan Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079107#M204605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE would be your best bet, you can configure MAB on the the ports and use profiling to profile the devices. So if a phone is profiled they get assigned to the voice vlan, the client behind it can be identified via dhcp attributes..etc. Then you can assign them to the admin vlan, while setting the default vlan on the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 07:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079107#M204605</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-18T07:09:13Z</dc:date>
    </item>
    <item>
      <title>Dynamic Vlan Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079108#M204675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Neil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add to what Tarik said, I would also describe that can be used with whatever radius server you have.&lt;/P&gt;&lt;P&gt;in ISE (Tarik, correct me if I am wrong) the devices and getting profiled automatically depending on many attributes and the device can be distinguished if it is an ip phone, laptop, ipad...etc. and based on that the VLAN assignmed is applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With other radius servers you need to statically specify what VLANs should the users be put in. The VLAN assignment is being done based on username the user is using OR the mac address the device provides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two weeks ago I implemented the same scenario using cisco ACS 5.3 radius server where users have multiple AD users and some other devices (ip phones, network printers...etc) and the VLAN assignment happens based on the AD group or the type of the device.&lt;/P&gt;&lt;P&gt;I manually added the mac addresses of priners in a group, ip phones in different group..etc. and I configured the ACS to assign the VLAN based on that gorup. with ISE what I know is it detects the device type automatically (you have to configure a profile for device types though) and based on that it assigns a VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to notice one thing though, if you are configuring the switch for the dot1x authentication you need to add a configuraiton in the radius in order to tell the switch to use teh VOICE vlan (not DATA vlan) for the phones. Otherwise the phone will use DATA VLAN when authenticated and not the voice VLAN which makes only one device; the phone or the PC attached to it, to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use cisco switches, you need to return to cisco-av-pair attribute with value "&lt;STRONG style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif; text-align: justify;"&gt;device-traffic-class=voice&lt;/STRONG&gt;" to the phones when they authenticate. I used this with non-cisco phones and it works like a charm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if there is anything else you need to know about dynamic vlan assignment. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that was useful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 13:01:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079108#M204675</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-01-27T13:01:55Z</dc:date>
    </item>
    <item>
      <title>Dynamic Vlan Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079109#M204766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 19:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment/m-p/2079109#M204766</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-27T19:33:16Z</dc:date>
    </item>
  </channel>
</rss>

