<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Just looking for good documentation to learn about VLAN Assignment. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482802#M510640</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if you will find specific documentation on this, but the only thing you need to add to your authorization profiles is a VLAN assignment.&amp;nbsp; Then the rest is just crafting your authorization rules to apply the correct authorization profile that has the VLAN you want assigned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are doing centralized wireless, i.e. not FlexConnect, as long as the WLC has an interface on the VLAN assigned from ISE the user will get moved to that VLAN.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In FlexConnect it gets a bit tricker.&amp;nbsp; If the VLAN is in use by another SSID then there is no problem assigning the VLAN to a FlexConnect client.&amp;nbsp; If the VLAN isn't used by any WLAN then you first have to "push" the VLAN information out the the FlexConnect AP.&amp;nbsp; The way I have done that in the past is using the AAA VLAN-ACL mapping tab in your FlexConnect group.&amp;nbsp; Add whatever VLANs you need there and assign "none" as the ingress and egress ACL.&amp;nbsp; That will make the AP aware of the VLAN and allow the VLAN assignment in ISE to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Apr 2018 19:52:09 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-04-18T19:52:09Z</dc:date>
    <item>
      <title>Just looking for good documentation to learn about VLAN Assignment.</title>
      <link>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482801#M510639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone lead me to good articles in relation to understanding/configuring VLAN assignment?&amp;nbsp; i.e. one SSID assigning vlan based on AD group and/or network location?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 18:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482801#M510639</guid>
      <dc:creator>jmilay</dc:creator>
      <dc:date>2018-04-18T18:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Just looking for good documentation to learn about VLAN Assignment.</title>
      <link>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482802#M510640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if you will find specific documentation on this, but the only thing you need to add to your authorization profiles is a VLAN assignment.&amp;nbsp; Then the rest is just crafting your authorization rules to apply the correct authorization profile that has the VLAN you want assigned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are doing centralized wireless, i.e. not FlexConnect, as long as the WLC has an interface on the VLAN assigned from ISE the user will get moved to that VLAN.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In FlexConnect it gets a bit tricker.&amp;nbsp; If the VLAN is in use by another SSID then there is no problem assigning the VLAN to a FlexConnect client.&amp;nbsp; If the VLAN isn't used by any WLAN then you first have to "push" the VLAN information out the the FlexConnect AP.&amp;nbsp; The way I have done that in the past is using the AAA VLAN-ACL mapping tab in your FlexConnect group.&amp;nbsp; Add whatever VLANs you need there and assign "none" as the ingress and egress ACL.&amp;nbsp; That will make the AP aware of the VLAN and allow the VLAN assignment in ISE to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 19:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482802#M510640</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-04-18T19:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Just looking for good documentation to learn about VLAN Assignment.</title>
      <link>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482803#M510641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE Config guide should help you with how to create authorization profile with VLAN based assignment&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 11:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482803#M510641</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-04-19T11:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Just looking for good documentation to learn about VLAN Assignment.</title>
      <link>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482804#M510642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the information.&amp;nbsp; This will definitely get me headed in the right direction.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 13:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/just-looking-for-good-documentation-to-learn-about-vlan/m-p/3482804#M510642</guid>
      <dc:creator>jmilay</dc:creator>
      <dc:date>2018-04-19T13:10:00Z</dc:date>
    </item>
  </channel>
</rss>

