<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLAN Interface Groups with Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821750#M474775</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;, based on my understanding in your statement, it is much better to have the wireless in 1 VLAN?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 04:23:20 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2019-03-19T04:23:20Z</dc:date>
    <item>
      <title>WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821200#M474697</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is it possible in Cisco ISE to push wireless interface group for WLAN 802.1x?&lt;/P&gt;
&lt;P&gt;Also, is it possible for ISE to have an authorization policy like the following logic,&lt;/P&gt;
&lt;P&gt;1. Each floors will be configured with a wireless ap-group (example, Level 1 will be having AP-Group A).&lt;/P&gt;
&lt;P&gt;2. Each AP-group will be assigned into a VLAN (example, AP-Group-A will be having VLAN 10).&lt;/P&gt;
&lt;P&gt;3. In ISE, if the users connects to this particular ap-group (AP-Group-A) then ISE will push VLAN10.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 10:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821200#M474697</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-18T10:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821291#M474699</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- you could group your APs per floor and give them a specific name.&lt;/P&gt;
&lt;P&gt;in the author Policy put a condition for called-station ID begins or ends with the specifies group name.&lt;/P&gt;
&lt;P&gt;Point to an author profile that u can push a vlan like vlan 10 for example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate if helpful&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821291#M474699</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-18T13:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821312#M474701</link>
      <description>&lt;P&gt;Vlan Groups (for Cisco Switches) and Interface Groups (for Cisco WLCs) can be done if you simply return the "name" of the Group in your ISE Authorization Profile.&amp;nbsp; I do it all the time for WLC's and for Cisco Switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And yes you can return Authorization Profiles for just about any condition that you can think of.&amp;nbsp; But I would recommend using something that works universally. Groups are a good abstraction - and they also take care of DHCP exhaustion by performing DHCP snooping.&amp;nbsp; If the client doesn't get a DHCP response then the Switch/WLC just runs the hash algorithm again.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 20:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821312#M474701</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-03-18T20:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821314#M474704</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;, thanks for the feedback.&lt;/P&gt;
&lt;P&gt;What in particular should I use for the authorization policy in ISE for me to have if user is connecting to this particular "AP-Group", then push the VLAN?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821314#M474704</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-18T14:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821563#M474774</link>
      <description>&lt;P&gt;I am not sure if you are just giving an example or really trying to have AP groups per floor on different VLANs.&amp;nbsp; I think that will be disastrous as you can't control client roaming that precisely.&amp;nbsp; It is completely possible on client on floor 3 will roam from a floor AP to a floor 2 AP back to a floor 3 AP as they walk around floor 3.&amp;nbsp; If you move the client onto a different VLAN when it hit an AP on floor 2 the client will most likely be stuck because it will have an IP from floor 3 and not know to refresh.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 20:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821563#M474774</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-18T20:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821750#M474775</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;, based on my understanding in your statement, it is much better to have the wireless in 1 VLAN?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 04:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821750#M474775</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-19T04:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821759#M474776</link>
      <description>&lt;P&gt;I am just cautioning that you have to think of client roaming and not necessarily always roaming to an AP on the same floor.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 05:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3821759#M474776</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-19T05:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3822027#M474777</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;, actually there is a real life scenario there that i need to take into consideration.&lt;/P&gt;
&lt;P&gt;so every time a client goes to different floor and have a different ap-group, ISE needs to send out CoA to grab a new IP in that ap-group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3822027#M474777</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-19T13:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3822083#M474778</link>
      <description>&lt;P&gt;You are talking about client physically walking from floor 1 to floor 2, but I am saying that is not how wireless works. Client could be walking on floor 2 and be roaming between APs on floor 1 and floor 2.&amp;nbsp; If those are mapped to different VLANs you are going to most likely disrupt the client's communication.&amp;nbsp; The client will not know to refresh their IP because there is no network adapter event.&amp;nbsp; The client is simply roaming on the same SSID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would test it in the lab before trying anything like this in productions.&amp;nbsp; Setup two APs each with different VLAN assignment and roam between the two and watch your client get stranded when it roams from one to the other.&amp;nbsp; I could be wrong, but I pretty sure you will see a disruption.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 14:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3822083#M474778</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-19T14:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3954402#M474779</link>
      <description>&lt;P&gt;Hi Arne,&lt;/P&gt;&lt;P&gt;How is this configured on the WLAN and ISE? Is there documentation/examples available that you know of?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 00:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3954402#M474779</guid>
      <dc:creator>gschmitt.ngit</dc:creator>
      <dc:date>2019-11-07T00:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN Interface Groups with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3954554#M474780</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323730"&gt;@gschmitt.ngit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're asking about the dynamic VLAN override on a Cisco WLC? The concept is that you return a VLAN name (string) instead of the VLAN number (numeric). On the WLC you always give an Interface a name. That WLC Interface Name string would be a valid string that ISE can return to the WLC during a RADIUS authentication. If your WLC is using Interface Groups, then put all your interfaces that you want/need into that Group, and tell ISE to return the Interface Group name string to the WLC during RADIUS auth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;below is an example from an AirOS WLC which has an Interface Group with a very creative name of "test".&amp;nbsp; That Group contains one VLAN at the moment - vlan 390, whose Interface is called 'dmz'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="comm04.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/48783iF97FAA9542C01E29/image-size/large?v=v2&amp;amp;px=999" role="button" title="comm04.PNG" alt="comm04.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In ISE I would return an Authorization profile that looks like this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="comm05.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/48784i464DEE13EF1DD300/image-size/large?v=v2&amp;amp;px=999" role="button" title="comm05.PNG" alt="comm05.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to ensure that the WLC WLAN is configured to allow AAA Override.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="comm06.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/48785iB1988CE9ECBB3BFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="comm06.PNG" alt="comm06.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 07:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlan-interface-groups-with-cisco-ise/m-p/3954554#M474780</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-07T07:40:42Z</dc:date>
    </item>
  </channel>
</rss>

