<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius distant site in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3817927#M484359</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm working on a Windows radius server.&lt;/P&gt;&lt;P&gt;The radius authenticate by computers name and MAC address so they get specific VLAN.&lt;/P&gt;&lt;P&gt;Let's take an example:&lt;/P&gt;&lt;P&gt;I authenticate by computer name so i get VLAN 2.&lt;/P&gt;&lt;P&gt;If i need to go to a distant site it will still get VLAN 2 but i want the computer to get the VLAN from the distant site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible ?&lt;/P&gt;&lt;P&gt;If yes then which policy do i need to configure ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your attention.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:50:09 GMT</pubDate>
    <dc:creator>Teayuu</dc:creator>
    <dc:date>2019-03-12T09:50:09Z</dc:date>
    <item>
      <title>Radius distant site</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3817927#M484359</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm working on a Windows radius server.&lt;/P&gt;&lt;P&gt;The radius authenticate by computers name and MAC address so they get specific VLAN.&lt;/P&gt;&lt;P&gt;Let's take an example:&lt;/P&gt;&lt;P&gt;I authenticate by computer name so i get VLAN 2.&lt;/P&gt;&lt;P&gt;If i need to go to a distant site it will still get VLAN 2 but i want the computer to get the VLAN from the distant site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible ?&lt;/P&gt;&lt;P&gt;If yes then which policy do i need to configure ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your attention.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3817927#M484359</guid>
      <dc:creator>Teayuu</dc:creator>
      <dc:date>2019-03-12T09:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Radius distant site</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3818990#M484360</link>
      <description>&lt;P&gt;You can either create rules based on network device or location names:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If Location A then VLAN X.&lt;/LI&gt;
&lt;LI&gt;If Location B then VLAN Y.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That doesn't scale well.&amp;nbsp; The better solution is to use a consistent VLAN naming scheme and pass the VLAN name not the VLAN #.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Location A has VLAN 2 name "Data".&lt;/LI&gt;
&lt;LI&gt;Location B has VLAN 20 named "Data".&lt;/LI&gt;
&lt;LI&gt;ISE results assigns VLAN "Data".&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This allows the user to fall onto the correct VLAN not matter the location.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 17:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3818990#M484360</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-13T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Radius distant site</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821115#M484361</link>
      <description>&lt;P&gt;Hello, thank you for your anwser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i did a new network policy, using the name of the client (in my situation it's a switch) then it work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example: if the request is from switch A and it's a computer in the AD group then assign VLAN A&lt;/P&gt;&lt;P&gt;if the request is from switch B and it's a computer in the AD group then assign VLAN B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 07:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821115#M484361</guid>
      <dc:creator>Teayuu</dc:creator>
      <dc:date>2019-03-18T07:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Radius distant site</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821545#M484362</link>
      <description>&lt;P&gt;That solution works, but doesn't scale well if you have many sites.&amp;nbsp; You are better using a standardize VLAN naming scheme and passing the VLAN name instead of the #.&amp;nbsp; Glad you got a solution that works.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 20:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821545#M484362</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-18T20:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Radius distant site</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821836#M484363</link>
      <description />
      <pubDate>Mon, 25 Mar 2019 09:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-distant-site/m-p/3821836#M484363</guid>
      <dc:creator>Teayuu</dc:creator>
      <dc:date>2019-03-25T09:26:41Z</dc:date>
    </item>
  </channel>
</rss>

