<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN change CoA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508821#M520243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one of our customers have the following scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Wired access where employees and guests can connect&lt;/LI&gt;&lt;LI&gt;Switchports by default on corporate VLAN X&lt;/LI&gt;&lt;LI&gt;CWA for any non-domain PC with self registration portal&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the customer asked to differentiate Guest traffic based on VLAN (all users authenticated on CWA portal with guest credentials).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done some test but basically the problem is that the endpoint does not recognize that the VLAN has changed and the IP is not beign refreshed by the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any suggestion in order to achieve that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The objective is to have something that could differentiate guest traffic like another VLAN for guest traffic, another network ecc. I have tried to see if SGT could be an option but basically the target device (web proxy) do not recognize the TrustSec tag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think that assign the same network on different VLAN using VRFs could be an option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Nov 2017 13:24:30 GMT</pubDate>
    <dc:creator>matteodapozzo</dc:creator>
    <dc:date>2017-11-02T13:24:30Z</dc:date>
    <item>
      <title>VLAN change CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508821#M520243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one of our customers have the following scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Wired access where employees and guests can connect&lt;/LI&gt;&lt;LI&gt;Switchports by default on corporate VLAN X&lt;/LI&gt;&lt;LI&gt;CWA for any non-domain PC with self registration portal&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the customer asked to differentiate Guest traffic based on VLAN (all users authenticated on CWA portal with guest credentials).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done some test but basically the problem is that the endpoint does not recognize that the VLAN has changed and the IP is not beign refreshed by the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any suggestion in order to achieve that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The objective is to have something that could differentiate guest traffic like another VLAN for guest traffic, another network ecc. I have tried to see if SGT could be an option but basically the target device (web proxy) do not recognize the TrustSec tag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think that assign the same network on different VLAN using VRFs could be an option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508821#M520243</guid>
      <dc:creator>matteodapozzo</dc:creator>
      <dc:date>2017-11-02T13:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508822#M520244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,yes you&amp;nbsp; can use different VRF ,as you know i am sure u can have different VRF for management other for DATA ,other for VOICE , in my deployment i have them and guest VLAN . But i have only wireless guest not wired ,nvm. I think you can creat new &lt;SPAN class="nested xwtBreadcrumb"&gt;&lt;A&gt;Authorization Profiles&lt;/A&gt;&lt;SPAN class="xwtBreadcrumbSeparator"&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast"&gt;New Authorization Profile and tag the VLAN you want for guest &lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/112928_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After just add this profile to authorization rule .&lt;/P&gt;&lt;P&gt;You can test this too &lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/112929_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508822#M520244</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-11-02T13:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508823#M520245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you ognyan for your feedback, I appreciate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to stay away from VLAN DHCP Release option because we don't know if the Guest clients have ActiveX o&lt;SPAN style="font-size: 10pt;"&gt;r Java support. Please let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks again for your answer!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508823#M520245</guid>
      <dc:creator>matteodapozzo</dc:creator>
      <dc:date>2017-11-02T13:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508824#M520246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Existing discussions in the community on same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/thread/81859&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/thread/78818?start=0&amp;amp;tstart=0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 14:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-coa/m-p/3508824#M520246</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-02T14:14:52Z</dc:date>
    </item>
  </channel>
</rss>

