<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and dynamic vlan assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/3335841#M40149</link>
    <description>&lt;P&gt;Hi Guys ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have an ISE v2.1&amp;nbsp;&amp;nbsp; i am try to do&amp;nbsp; dynamic vlan assignment&amp;nbsp; , vlan 24&amp;nbsp; for voice&amp;nbsp; an vlan 26 for data ,&lt;/P&gt;
&lt;P&gt;the traditional way is to add manually the mac address of each device into the appropriate group then use profiling to&amp;nbsp; map this group to the required vlan.&amp;nbsp; even with this&amp;nbsp; i see all the MACs in vlan 24 , dont know what i have done wrong here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 24&amp;nbsp;&amp;nbsp;&amp;nbsp; xx.x.x.x.x.x&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/9 &lt;BR /&gt;&amp;nbsp; 24&amp;nbsp;&amp;nbsp;&amp;nbsp; y.y.y.y.y.yy.y&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/9&lt;/P&gt;
&lt;P&gt;can you please explain what should be the right way to accomplish this .&lt;/P&gt;
&lt;P&gt;also i was told there is an other intelligent way for&amp;nbsp; dynamic vlan assignment , here you dont need to enter manually the mac addresses but using the specific sensor/protocol the ISE will be will be able to detect&amp;nbsp; classify the endpoints based on their profiles&lt;/P&gt;
&lt;P&gt;thanx in advance&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2018 12:57:05 GMT</pubDate>
    <dc:creator>54545</dc:creator>
    <dc:date>2018-02-22T12:57:05Z</dc:date>
    <item>
      <title>ISE Dynamic VLAN assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/2857358#M40147</link>
      <description>&lt;P&gt;So we're looking to implement dynamic VLAN assignment for user-end host devices and we're a little fuzzy on the details of how to get it going. &amp;nbsp;We were under the assumption that ISE (PSN) speaks directly to AD to learn information about the host device such as if it's a domain device or even what OU or security group it belonged to. But after going through some documentation that turned up from a google search it would seem this is an incorrect assumption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/sec-ieee-8021x-vlan-assign.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/sec-ieee-8021x-vlan-assign.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;alludes to it actually being that the PSN seeks information about the host device via a local RADIUS server which in turn queries AD for the desired information. At the moment our RADIUS server simply verifies with AD that the host is in fact a domain client. The doc above says we must add some "&lt;SPAN&gt;vendor-specific tunnel attributes" to the RADIUS server's query in order to have VLAN information returned to the PSN and then passed onto the switchport.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does this mean that the PSN does not communicate directly to AD for such information as domain credentials and OU/security group membership during 802.1x authentication?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/2857358#M40147</guid>
      <dc:creator>pj0503311</dc:creator>
      <dc:date>2019-03-11T06:32:12Z</dc:date>
    </item>
    <item>
      <title>no, it does it during the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/2857359#M40148</link>
      <description>&lt;P&gt;no, it does it during the authorization phase using the authorization policy sets&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 18:48:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/2857359#M40148</guid>
      <dc:creator>aman.diwakar</dc:creator>
      <dc:date>2016-03-02T18:48:37Z</dc:date>
    </item>
    <item>
      <title>ISE and dynamic vlan assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/3335841#M40149</link>
      <description>&lt;P&gt;Hi Guys ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have an ISE v2.1&amp;nbsp;&amp;nbsp; i am try to do&amp;nbsp; dynamic vlan assignment&amp;nbsp; , vlan 24&amp;nbsp; for voice&amp;nbsp; an vlan 26 for data ,&lt;/P&gt;
&lt;P&gt;the traditional way is to add manually the mac address of each device into the appropriate group then use profiling to&amp;nbsp; map this group to the required vlan.&amp;nbsp; even with this&amp;nbsp; i see all the MACs in vlan 24 , dont know what i have done wrong here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 24&amp;nbsp;&amp;nbsp;&amp;nbsp; xx.x.x.x.x.x&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/9 &lt;BR /&gt;&amp;nbsp; 24&amp;nbsp;&amp;nbsp;&amp;nbsp; y.y.y.y.y.yy.y&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/9&lt;/P&gt;
&lt;P&gt;can you please explain what should be the right way to accomplish this .&lt;/P&gt;
&lt;P&gt;also i was told there is an other intelligent way for&amp;nbsp; dynamic vlan assignment , here you dont need to enter manually the mac addresses but using the specific sensor/protocol the ISE will be will be able to detect&amp;nbsp; classify the endpoints based on their profiles&lt;/P&gt;
&lt;P&gt;thanx in advance&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 12:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dynamic-vlan-assignment/m-p/3335841#M40149</guid>
      <dc:creator>54545</dc:creator>
      <dc:date>2018-02-22T12:57:05Z</dc:date>
    </item>
  </channel>
</rss>

