<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic VLAN assignment for wired and wireless connections in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497872#M429092</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi leonard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;main step are for&amp;nbsp; wireless are(using controller+radius):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 Use 802.1x as auth method for you wlan&lt;/P&gt;&lt;P&gt;2 On controller select the option AAA Override (Advamced TAB under WLAN)&lt;/P&gt;&lt;P&gt;3 Configure your radius (and cliente) to pass to controller tunnel type you need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to do the most on your Radius but there are good docs about "how to implement" Dynamic vlam assignment using ACS or IAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 May 2011 07:07:53 GMT</pubDate>
    <dc:creator>alessandro.dona</dc:creator>
    <dc:date>2011-05-27T07:07:53Z</dc:date>
    <item>
      <title>Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497862#M429074</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've setup our Cisco ACS 3.3 appliance to authenticate users connecting via wireless and wired connections (802.1x). I've succesfully managed the above but now would like to assign authenticated users to a specific VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I setup ACS to assign different VLAN-ids based on the AAA-client used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've got roaming users connecting to the network at multiple locations. &lt;/P&gt;&lt;P&gt;On location A I would like wired users to be assigned to VLAN 100 and wireless users to VLAN 101.&lt;/P&gt;&lt;P&gt;On location B I would like wired users to be assigned VLAN 50 and 51 for wired and wireless connections. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the above possible? So far I've only been able to specify one VLAN per user / group.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497862#M429074</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2019-03-10T21:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497863#M429075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using radius as the authentication, if you are, you can setup the attributes under the user to specify the VLAN you want them to be assigned to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 14:23:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497863#M429075</guid>
      <dc:creator>ecarrasquillo</dc:creator>
      <dc:date>2005-09-06T14:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497864#M429078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we're useing Radius authentication. I know I can assign the user a VLAN. But what I actually want is to assign the user different VLAN-ids based on the location they're requesting access from. &lt;/P&gt;&lt;P&gt;So wireless users get vlan 101 (for example) and wired users get vlan 102.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 15:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497864#M429078</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2005-09-06T15:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497865#M429081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Erik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you solved your problems?&lt;/P&gt;&lt;P&gt;I have the same issue aand i would like to know if it is possible or not assign VLAN-ID based on AAA client type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alessandro.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jan 2010 16:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497865#M429081</guid>
      <dc:creator>alessandro.dona</dc:creator>
      <dc:date>2010-01-07T16:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497866#M429084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alessandro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We gave up on this with ACS 3.3.&lt;/P&gt;&lt;P&gt;The newer ACSes have more options with policies but I finally reverted to using IAS/NPS on which this is a simple task.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jan 2010 08:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497866#M429084</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2010-01-08T08:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497867#M429085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jan 2010 08:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497867#M429085</guid>
      <dc:creator>alessandro.dona</dc:creator>
      <dc:date>2010-01-08T08:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497868#M429086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's easy. Under group settings the last three attributes (given you have enabled them globally) are;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel-Type&amp;nbsp;&amp;nbsp; (Should be set to VLAN)&lt;/P&gt;&lt;P&gt;Tunnel-Medium-Type (Should be set to 802)&lt;/P&gt;&lt;P&gt;Tunnel-Private-Group-ID&amp;nbsp; (Your vlan id you wish to assign)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind you need to enable these settings first under Interface Configuration so they will show up under group settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you set up the local groups and map them to wlans. You can via External Databases -&amp;gt; Database Group Mappings map the local groups to Active Directory groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Voila.. dynamic vlan assigment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jan 2010 22:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497868#M429086</guid>
      <dc:creator>Kent Heide</dc:creator>
      <dc:date>2010-01-08T22:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497869#M429087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct when only one vlan-id has to be defined per user in the entire enterprise.&lt;/P&gt;&lt;P&gt;My question started with asking for multiple vlan-id's, assigned based on access-device (switch/ap/vpn/...). Your solution is not a solution for such an environment. A user can only be a member of one group, and there is no relation between access-devices and users in 3.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 09:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497869#M429087</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2010-01-11T09:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497870#M429088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alessandro and Erik,&lt;/P&gt;&lt;P&gt;I'm into the same situation.&lt;/P&gt;&lt;P&gt;Could you guys explain me exactly what you have done to solve this problem?&lt;/P&gt;&lt;P&gt;Best regards!&lt;/P&gt;&lt;P&gt;Leonardo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 21:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497870#M429088</guid>
      <dc:creator>leonardo.fell</dc:creator>
      <dc:date>2011-05-26T21:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497871#M429090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;test&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 21:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497871#M429090</guid>
      <dc:creator>leonardofell</dc:creator>
      <dc:date>2011-05-26T21:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497872#M429092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi leonard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;main step are for&amp;nbsp; wireless are(using controller+radius):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 Use 802.1x as auth method for you wlan&lt;/P&gt;&lt;P&gt;2 On controller select the option AAA Override (Advamced TAB under WLAN)&lt;/P&gt;&lt;P&gt;3 Configure your radius (and cliente) to pass to controller tunnel type you need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to do the most on your Radius but there are good docs about "how to implement" Dynamic vlam assignment using ACS or IAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2011 07:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497872#M429092</guid>
      <dc:creator>alessandro.dona</dc:creator>
      <dc:date>2011-05-27T07:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment for wired and wireless connections</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497873#M429093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks foy your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a wired 802.1x implemented in my network using freeradius as RADIUS server.&lt;/P&gt;&lt;P&gt;I'd like to use a different vlan on the wireless 802.1x.&lt;/P&gt;&lt;P&gt;Example: A user has the "TunnelPrivateGroupe=2" atribute . It means he will join the vlan with ID 2 when authenticated. On the wired it works properly, but I dont want to open this vlan (2) on my wireless network. I'd like to use another vlan to this user.&lt;/P&gt;&lt;P&gt;Regards!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2011 17:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-for-wired-and-wireless-connections/m-p/497873#M429093</guid>
      <dc:creator>leonardo.fell</dc:creator>
      <dc:date>2011-05-27T17:07:04Z</dc:date>
    </item>
  </channel>
</rss>

