<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The workaround for VLAN DHCP Release in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587629#M517442</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I agree, I would skip low impact mode if vlan enforcement is needed, it make little sense anyway. Closed mode moves between vlans and dhcp renew does work without issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2018 02:25:40 GMT</pubDate>
    <dc:creator>starvoise</dc:creator>
    <dc:date>2018-05-10T02:25:40Z</dc:date>
    <item>
      <title>The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587624#M517437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw the config example for CWA with catalyst or WLC.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html" rel="nofollow" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" rel="nofollow" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the guide, we don't recommend IP renew method by using VLAN DHCP release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the reason is renewing address require active-x and it's not 100% sure to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, my customer plan to use two DHCP servers.&lt;/P&gt;&lt;P&gt;One is for short DHCP lease time for 1st auth, and the other have the normal DHCP lease for 2nd auth.&lt;/P&gt;&lt;P&gt;Can we support their way to change IP address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 12:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587624#M517437</guid>
      <dc:creator>shkuzu</dc:creator>
      <dc:date>2018-03-06T12:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587625#M517438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1st For redirection you can add Vlan ID Just tick Vlan and set the ID before created on the device .&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115698_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;After guest successful registered and authenticated you can add other profile and change there vlan too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 13:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587625#M517438</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-03-06T13:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587626#M517439</link>
      <description>&lt;P&gt;It's not a problem for closed mode as you can push the vlan in the redirection authorization rule as shown above.&lt;/P&gt;
&lt;P&gt;Its an issue in low impact. The vlan dhcp release functionality works but the user experience is not good.&lt;/P&gt;
&lt;P&gt;We have used auto smart port macro in lab on 3650 and 3750-E to achieve it.&lt;/P&gt;
&lt;P&gt;&lt;A title="https://communities.cisco.com/thread/81859" href="https://community.cisco.com/thread/81859" target="_blank"&gt;https://communities.cisco.com/thread/81859&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I know of one customer which is trying to implement it in production.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 19:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587626#M517439</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2019-01-23T19:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587627#M517440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some of our customers are using short DHCP lease time and I have not heard any issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2018 02:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587627#M517440</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-09T02:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587628#M517441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another recommendation would be to register the endpoints of the users into an Endpoint group and after initial Authentication Rely on a authorization rule that simply permit to access if you’re  in that end point group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We call this guest remember me&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2018 03:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587628#M517441</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-09T03:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587629#M517442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I agree, I would skip low impact mode if vlan enforcement is needed, it make little sense anyway. Closed mode moves between vlans and dhcp renew does work without issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2018 02:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3587629#M517442</guid>
      <dc:creator>starvoise</dc:creator>
      <dc:date>2018-05-10T02:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783695#M517443</link>
      <description>&lt;P&gt;Jason, could you expand on this option? I'm trying to get DHCP renew working well for wired guest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My aim:&lt;BR /&gt;port has 802.1x falling back to MAB.&lt;BR /&gt;start in VLAN 150, move Guest to VLAN 400, Corp to 500.&lt;BR /&gt;[ignoring the Corp part here as only have a problem with Guest]&lt;BR /&gt;&lt;BR /&gt;Authz Rules:&lt;BR /&gt;- Guest_Access: if IG=GuestEndpoints then result = Guest (set VLAN 400)&lt;BR /&gt;- Redirect_To_Hotspot: if Guest_Flow then result = Hotspot (Redirect to Hotspot portal (sets IG=GuestEndpoints, no AUP, CoA=Terminate))&lt;BR /&gt;- Redirect_To_CWA: if Wired_MAB then result = WebAuth (Redirect to CWA (Self Reg Guest) portal (device reg disabled, AUP, success URL set to force HTTP GET so HotSpot kicks in))&lt;BR /&gt;&lt;BR /&gt;It runs through the policy quite nicely but the change of VLAN is not detected by the client. So far the best result i have is from setting a very short DHCP lease (2 minutes) in VLAN 150 - then, approx 16 pings time out from a continuous ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Admin &amp;gt; System &amp;gt; Settings &amp;gt; Profiling the CoA is set to Reauth. I tried Port Bounce but the client didn't see that (perhaps because it's a VM). Also the CoA option on the Hotspot portal (Reauth or Terminate) doesn't appear to make any difference.&lt;/P&gt;
&lt;P&gt;I am aware of the SmartPort Macro option but that requires certain switch models, and i want a more general solution.&lt;/P&gt;
&lt;P&gt;I've seen a few references by you to a 3-rule solution but can't find or work out the detail.&lt;/P&gt;
&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jan 2019 14:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783695#M517443</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2019-01-20T14:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783720#M517444</link>
      <description>Did you try with a real client? Perhaps your vm port is not going up and down?&lt;BR /&gt;&lt;BR /&gt;Are you sure your switch is bouncing port?&lt;BR /&gt;</description>
      <pubDate>Sun, 20 Jan 2019 15:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783720#M517444</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-20T15:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783850#M517445</link>
      <description>&lt;P&gt;CoA setting in Admin &amp;gt; System &amp;gt; Settings &amp;gt; Profiling (Reauth or Port Bounce) seems to make little difference - if set to Port Bounce then bounce happens when i delete the Endpoint from ISE but not when it joins.&lt;BR /&gt;CoA setting in Hotspot portal (Reauth or Terminate) makes no difference i can see.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the solution you have alluded to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 00:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783850#M517445</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2019-01-21T00:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783859#M517446</link>
      <description>What ISE release are you running?&lt;BR /&gt;Have you tried 2.4 with latest patch&amp;gt;?&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Jan 2019 01:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3783859#M517446</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-21T01:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3784318#M517447</link>
      <description>&lt;P&gt;Running 2.2 Patch 12.&lt;/P&gt;
&lt;P&gt;tried in the lab with 2.4 Patch 5 too - couldn't see any difference.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 15:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3784318#M517447</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2019-01-21T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: The workaround for VLAN DHCP Release</title>
      <link>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3784665#M517448</link>
      <description>Thanks I would recommend working through TAC as well.&lt;BR /&gt;&lt;BR /&gt;Again its not recommended to do vlan change for these various reasons. I provided some options that might help workaround your issues but ultimately trying to steer away from that.&lt;BR /&gt;&lt;BR /&gt;What would be a better solution would be to use segementation with SGTs so that you can separate devices using tags instead of VLAN/ips&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Jan 2019 03:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-workaround-for-vlan-dhcp-release/m-p/3784665#M517448</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-22T03:00:26Z</dc:date>
    </item>
  </channel>
</rss>

