<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 Authentication, MAB and set the Guest-VLAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681808#M232550</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we need some clarity from the scenario, based on the&amp;nbsp; command which is now considered as the "guest vlan" authentication event no response authorize vlan xxx, the acs (assuming a true guest vlan scenario and that mab is disabled) is no longer in the picture and&amp;nbsp; the port authorizes the client based on this command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree Nicolas we need to see exactly the issue is,&amp;nbsp; but I am sure we can both agree that there will be some additonal access&amp;nbsp; policies to configure since there are different guest vlans based on&amp;nbsp; which switches the clients are coming in from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jul 2011 08:20:51 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2011-07-18T08:20:51Z</dc:date>
    <item>
      <title>ACS 5.1 Authentication, MAB and set the Guest-VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681805#M232547</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possible to set the dot1x guest-vlan on a Catalyst Switch via ACS 5.2 dynamicly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to make MAB with known Devices (FAT-Clients, Notebooks,&amp;nbsp; Desktops, Printers) and unknown Devices.&lt;/P&gt;&lt;P&gt;I will set the VLAN dynamicly with dot1x per ACS. For known FAT-Clients, Notebooks etc. it's running well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for Printers it's more difficult because I have about 500 Printers in several IP-Segments on several Switches&lt;/P&gt;&lt;P&gt;and I will not make to much Rules in ACS for Grouping, Mapping and Authority-Rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Idea is to set the Guest-VLAN on every Switch, read them with ACS and use this for my Printers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem is that Guest-VLAN is set on more than 100 Switch and this guest-vlan is different on any Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I read the Geust-VLAN Value so that I can set this via ACS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Answers.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681805#M232547</guid>
      <dc:creator>biss-team</dc:creator>
      <dc:date>2019-03-11T01:13:23Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 Authentication, MAB and set the Guest-VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681806#M232548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no way to dynamically assign a guest vlan from the ACS server, what version of ios do most of your switches run?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Jul 2011 23:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681806#M232548</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-16T23:46:06Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 Authentication, MAB and set the Guest-VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681807#M232549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going a bit against Tarik here but I'm not sure to understand you fully.&lt;/P&gt;&lt;P&gt;If you have known devices, i.e. their mac addresses are in ACS, this is not guest vlan. This is MAB with dynamic vlan assignment. This is an easy task to do on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your point is that when ACS doesn't know a device it returns a specific vlan depending on given conditions. It can be possible if you are creative.&lt;/P&gt;&lt;P&gt;You can set your identity store options to still an "accept" even if the user was not found. From there you can assign a vlan dynamically. But it's technically not a guest vlan. You just grant access to MAB to unknown devices and give them a vlan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jul 2011 08:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681807#M232549</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-07-17T08:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Authentication, MAB and set the Guest-VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681808#M232550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we need some clarity from the scenario, based on the&amp;nbsp; command which is now considered as the "guest vlan" authentication event no response authorize vlan xxx, the acs (assuming a true guest vlan scenario and that mab is disabled) is no longer in the picture and&amp;nbsp; the port authorizes the client based on this command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree Nicolas we need to see exactly the issue is,&amp;nbsp; but I am sure we can both agree that there will be some additonal access&amp;nbsp; policies to configure since there are different guest vlans based on&amp;nbsp; which switches the clients are coming in from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 08:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681808#M232550</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-18T08:20:51Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 Authentication, MAB and set the Guest-VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681809#M232551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for Answers.&lt;/P&gt;&lt;P&gt;My only Solution is to configure any Switch in his own NDG. Than I can set a VLAN per NDG and my Problem is solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2011 09:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-authentication-mab-and-set-the-guest-vlan/m-p/1681809#M232551</guid>
      <dc:creator>biss-team</dc:creator>
      <dc:date>2011-07-25T09:20:51Z</dc:date>
    </item>
  </channel>
</rss>

