<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic parameter AutoSmartPort, dynamic dead action vlan in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438226#M527416</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we plan to use dynamic vlan with cisco switches (IOS Version 15.2.x) and cisco ISE (2.1.0), t&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;his works so far.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;For the error case, I would like to set the dead action vlan dynamically.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;The only possibility I know is the AutoSmartPort feature on the cisco switches.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;macro auto execute CRITICAL_AUTH_VLAN CAVLAN=7 {&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; if [[ $LINKUP == YES ]] &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; then&amp;nbsp; conf t&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; interface $INTERFACE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; macro description $TRIGGER&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; description CAVLAN_7&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if [[ $AUTH_ENABLED -eq YES ]]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; then&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication event server dead action reinitialize vlan $CAVLAN&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; end&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; if [[ $LINKUP == NO ]] &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; then&amp;nbsp; conf t&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; interface $INTERFACE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no macro description&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no description CAVLAN_44&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if [[ $AUTH_ENABLED -eq YES ]]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; then&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication event server dead action reinitialize vlan 44&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; end&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;macro auto global processing &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;On the ISE i use this in the Authorization Profile&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cisco-av-pair = auto-smart-port=CRITICAL_AUTH_VLAN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: is it possible to change the &lt;EM&gt;$CAVLAN value withe the "&lt;EM&gt;cisco-av-pair = auto-smart-port" Parameter?&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;for example: &lt;EM&gt;cisco-av-pair = auto-smart-port=CRITICAL_AUTH_VLAN &lt;EM&gt;CAVLAN=55 &lt;/EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;The background of the question is, the crit vlan should always have the value of the last successful logon (with dynamic vlan). &lt;/SPAN&gt;&lt;SPAN lang="en"&gt;There are about 10-15 dynamic vlans, if i could set the parameter CAVLAN on the ISE, i need only one macro on the switch, otherwise it would copy the macro 10-15 and only the vlan id would differ.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Aug 2017 13:00:39 GMT</pubDate>
    <dc:creator>ChristianBur</dc:creator>
    <dc:date>2017-08-24T13:00:39Z</dc:date>
    <item>
      <title>parameter AutoSmartPort, dynamic dead action vlan</title>
      <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438226#M527416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we plan to use dynamic vlan with cisco switches (IOS Version 15.2.x) and cisco ISE (2.1.0), t&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;his works so far.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;For the error case, I would like to set the dead action vlan dynamically.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;The only possibility I know is the AutoSmartPort feature on the cisco switches.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;macro auto execute CRITICAL_AUTH_VLAN CAVLAN=7 {&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; if [[ $LINKUP == YES ]] &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; then&amp;nbsp; conf t&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; interface $INTERFACE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; macro description $TRIGGER&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; description CAVLAN_7&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if [[ $AUTH_ENABLED -eq YES ]]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; then&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication event server dead action reinitialize vlan $CAVLAN&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; end&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; if [[ $LINKUP == NO ]] &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; then&amp;nbsp; conf t&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; interface $INTERFACE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no macro description&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no description CAVLAN_44&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if [[ $AUTH_ENABLED -eq YES ]]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; then&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication event server dead action reinitialize vlan 44&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&amp;nbsp; end&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt; fi&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;macro auto global processing &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;On the ISE i use this in the Authorization Profile&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cisco-av-pair = auto-smart-port=CRITICAL_AUTH_VLAN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: is it possible to change the &lt;EM&gt;$CAVLAN value withe the "&lt;EM&gt;cisco-av-pair = auto-smart-port" Parameter?&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN&gt;for example: &lt;EM&gt;cisco-av-pair = auto-smart-port=CRITICAL_AUTH_VLAN &lt;EM&gt;CAVLAN=55 &lt;/EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;The background of the question is, the crit vlan should always have the value of the last successful logon (with dynamic vlan). &lt;/SPAN&gt;&lt;SPAN lang="en"&gt;There are about 10-15 dynamic vlans, if i could set the parameter CAVLAN on the ISE, i need only one macro on the switch, otherwise it would copy the macro 10-15 and only the vlan id would differ.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2017 13:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438226#M527416</guid>
      <dc:creator>ChristianBur</dc:creator>
      <dc:date>2017-08-24T13:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: parameter AutoSmartPort, dynamic dead action vlan</title>
      <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438227#M527417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you cannot specify variables in the A/V pair.&amp;nbsp; ASP is generally tricky on switchports with RADIUS authorization since they write to switch config, not just temporary config elements in mem for given session.&amp;nbsp; Have you looked at session-aware command logic that would allow policy template to set the desired behavior?&amp;nbsp; ISE also supports the retrieval of service and interface templates via RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 08:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438227#M527417</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-25T08:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: parameter AutoSmartPort, dynamic dead action vlan</title>
      <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438228#M527418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly this is the tick, the command (&lt;EM&gt;authentication event server dead action reinitialize vlan) &lt;/EM&gt;should NOT be session-aware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the radius servers are not reachable or down and e.g. the radius session expires, the clients should use the vlan of the last successful logon. If the commando is session-aware, the setting disappears after the radius session expires.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I now have to create a single macro for each access vlan?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 09:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438228#M527418</guid>
      <dc:creator>ChristianBur</dc:creator>
      <dc:date>2017-08-25T09:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: parameter AutoSmartPort, dynamic dead action vlan</title>
      <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438229#M527419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a unique use case, so cannot say I have had similar request.&amp;nbsp; Others reviewing thread may be able to comment on their experience, but question is more specific to switching team and options to achieve desired goal are limited to ASP feature, or if able to leverage IBNS 2.0 policy to achieve.&amp;nbsp; May even be able to achieve via EMM, but always a balance between complexity and utility. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I recall, the critical VLAN initiates on reauth or connection state change such that existing sessions not impacted.&amp;nbsp; It appears that you are trying to permit existing host access to same VLAN after AAA down.&amp;nbsp; Of course this would allow any endpoint that connects to port to get the privs of previous host.&amp;nbsp; Critical VLAN is often used to provide a minimum common denominator access when AAA down. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Aug 2017 17:37:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/3438229#M527419</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-26T17:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: parameter AutoSmartPort, dynamic dead action vlan</title>
      <link>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/5040453#M588131</link>
      <description>&lt;P&gt;very good question and idea that I also faced.&lt;BR /&gt;but there is no answer in this thread as to whether anyone has solved this problem to automatically send the vlan number for&amp;nbsp;&lt;EM&gt;authentication event server dead action reinitialize vlan&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;/Lukasz&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 08:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/parameter-autosmartport-dynamic-dead-action-vlan/m-p/5040453#M588131</guid>
      <dc:creator>Lukasz Luczak</dc:creator>
      <dc:date>2024-03-15T08:10:40Z</dc:date>
    </item>
  </channel>
</rss>

