<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and VLAN Assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3402425#M548280</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We have a WiSM2 (ver 8.2.167.6) providing an 802.1x wireless profile to staff and students.&amp;nbsp; RADIUS is in the form of ISE (ver 2.3.0.298) that uses MS Active Directory as the database.&amp;nbsp; Depending on which AD group a client belongs to will determine which VLAN Tag ISE sends to the WLC, and therefore which VLAN the wireless users is assiged to.&amp;nbsp; This setup works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem I have is that on a particular busy day (hosting a staff conference) we ran out of IP addresses on the Staff VLAN so new users could authenticate to ISE but were unable to get on the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The simplest workaround is just to increase the size of the DHCP scope, however I am reluctant to create a very large subnet.&amp;nbsp; The only other way I can thing of is to create new AD groups, splitting staff into the groups and getting ISE to use different VLAN tags for each AD group.&amp;nbsp; However we have a lot of staff and the administrative overhead for this approach will not be welcomed by the Server team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any other way I can split staff onto more than one VLAN using the ISE?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:58:57 GMT</pubDate>
    <dc:creator>terrywatson651</dc:creator>
    <dc:date>2020-02-21T18:58:57Z</dc:date>
    <item>
      <title>ISE and VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3402425#M548280</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We have a WiSM2 (ver 8.2.167.6) providing an 802.1x wireless profile to staff and students.&amp;nbsp; RADIUS is in the form of ISE (ver 2.3.0.298) that uses MS Active Directory as the database.&amp;nbsp; Depending on which AD group a client belongs to will determine which VLAN Tag ISE sends to the WLC, and therefore which VLAN the wireless users is assiged to.&amp;nbsp; This setup works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem I have is that on a particular busy day (hosting a staff conference) we ran out of IP addresses on the Staff VLAN so new users could authenticate to ISE but were unable to get on the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The simplest workaround is just to increase the size of the DHCP scope, however I am reluctant to create a very large subnet.&amp;nbsp; The only other way I can thing of is to create new AD groups, splitting staff into the groups and getting ISE to use different VLAN tags for each AD group.&amp;nbsp; However we have a lot of staff and the administrative overhead for this approach will not be welcomed by the Server team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any other way I can split staff onto more than one VLAN using the ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3402425#M548280</guid>
      <dc:creator>terrywatson651</dc:creator>
      <dc:date>2020-02-21T18:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3403377#M548281</link>
      <description>&lt;P&gt;Use interface groups at the WiSM, then use the Airespace-Interface-Name attribute to tell the WLC which interface-group name to use, rather than the VLAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using interface-groups, the WLC will choose which VLAN to put the client on based on which interfaces are in the interface-group.&amp;nbsp; You could have up-to 64 interfaces in an interface-group at the WiSM2, so if you don't like large subnets you could create up-to 64 /24 subnets (they can be bigger or smaller though) and add them to one interface-group, then attach that to the WLAN.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3403377#M548281</guid>
      <dc:creator>craig.beck</dc:creator>
      <dc:date>2018-06-21T14:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3407045#M548282</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Sorry for the delayed response, been on holiday.&amp;nbsp; Yes this has proved to be the solution, so thank you for taking the tine to respond.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terry&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 07:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-vlan-assignment/m-p/3407045#M548282</guid>
      <dc:creator>terrywatson651</dc:creator>
      <dc:date>2018-06-28T07:46:41Z</dc:date>
    </item>
  </channel>
</rss>

