<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trustsec and Areohive Wireless. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474683#M493328</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;I have a customer who is implementing Cisco Trustsec with ISE as the authenticator. The Areohive wireless is authenticating against ISE.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;The Areohive APs are plugged in to a Cisco 3650 switch, is it possible to assign a SGT to en endpoint on the wireless network and add the tag as they enter the trustsec domain? &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thank You,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;-Cor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:09:19 GMT</pubDate>
    <dc:creator>Cory Peterson</dc:creator>
    <dc:date>2019-03-11T07:09:19Z</dc:date>
    <item>
      <title>Trustsec and Areohive Wireless.</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474683#M493328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;I have a customer who is implementing Cisco Trustsec with ISE as the authenticator. The Areohive wireless is authenticating against ISE.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;The Areohive APs are plugged in to a Cisco 3650 switch, is it possible to assign a SGT to en endpoint on the wireless network and add the tag as they enter the trustsec domain? &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thank You,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;-Cor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474683#M493328</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2019-03-11T07:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec and Areohive Wireless.</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474684#M493331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cory,&lt;/P&gt;&lt;P&gt;interesting that the Aerohive is not listed in the ISE compatibility guide and you say you are authenticating against ISE:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" title="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html"&gt;http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you were indeed authenticating wireless users against ISE, (and accounting is operational in order to build a complete session in ISE), then SXP could be used on ISE to forward the IP-SGT mapping towards an enforcement point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I am concerned that the AP is not compatible as I do not see it in the matrix. Therefore, what you could do is add VLAN-SGT mapping on the 3650. Each wireless SSID, mapped to a VLAN, can have SGT's assigned on the 3650 via static VLAN-SGT mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will that work for you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Jonothan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2016 14:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474684#M493331</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2016-10-14T14:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec and Areohive Wireless.</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474685#M493338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Areohive is working for basic Radius Authentication and we are able to dynamically change VLANs on the Areohive using Radius attributes in ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My suggestion to the client was to use multiple VLANs and VLAN-SGT mappings also, but they did not want to go that route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I should be able to use the AP Uplink as the enforcement point?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will let you know how it goes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Cory&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2016 14:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-and-areohive-wireless/m-p/3474685#M493338</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2016-10-14T14:39:55Z</dc:date>
    </item>
  </channel>
</rss>

