<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic VLAN assignment using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044492#M558818</link>
    <description>&lt;P&gt;As the other gentleman here said. Yes you can, but be careful since AP usually joins the wireless controller and needs an IP to join. If for some reason the DHCP fails and AP does not join, then you will have a problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can probably whitelist the MAC address and assign a VLAN. As more AP's are used you can use the same whitelist to add AP MAC addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also profile an AP that adds the MAC to endpoint ID group and use the endpoint ID group in the authorization policy.&lt;/P&gt;
&lt;P&gt;Test these things before implementing it. Make sure your session for AP does not timeout very frequently causing reauthentication&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Krishnan&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2020 19:51:35 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2020-03-11T19:51:35Z</dc:date>
    <item>
      <title>Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044338#M558797</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if it is possible to use ISE (Version 2.4) to dynamically assign VLANs for wireless access points when they are plugged into a switchport. Our organization requires AP's to be on a separate VLAN from the user VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if so, what steps do I need to take to implement this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 16:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044338#M558797</guid>
      <dc:creator>z28thebridge</dc:creator>
      <dc:date>2020-03-11T16:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044347#M558799</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- As far as I understand &lt;STRONG&gt;yes&lt;/STRONG&gt;, but probably only using MAB (Mac Authentication Bypass); the MAC addresses of the AP"s can be on an LDAP server (possibly MS AD-too). Switch with MAB-settings will use radius to query ISE. Configuration details require some basic studying of ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 16:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044347#M558799</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-03-11T16:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044460#M558815</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Are those standalone AP's, or LAP's (which require a WLC to function)? If LAP's, are you running FlexConnect or not? It can be done anyways, but the solution depends on the above questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 19:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044460#M558815</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-11T19:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044492#M558818</link>
      <description>&lt;P&gt;As the other gentleman here said. Yes you can, but be careful since AP usually joins the wireless controller and needs an IP to join. If for some reason the DHCP fails and AP does not join, then you will have a problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can probably whitelist the MAC address and assign a VLAN. As more AP's are used you can use the same whitelist to add AP MAC addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also profile an AP that adds the MAC to endpoint ID group and use the endpoint ID group in the authorization policy.&lt;/P&gt;
&lt;P&gt;Test these things before implementing it. Make sure your session for AP does not timeout very frequently causing reauthentication&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Krishnan&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 19:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044492#M558818</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2020-03-11T19:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044981#M558841</link>
      <description>&lt;P&gt;They are LAP's and we are running FlexConnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 14:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4044981#M558841</guid>
      <dc:creator>z28thebridge</dc:creator>
      <dc:date>2020-03-12T14:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN assignment using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4045076#M558848</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; As MAB is really insecure in the end, even if it's combined with Profiling and Anomalous EndPoint Detection, i would chose to authenticate the AP via 802.1x. Depending on the WLC software/hardware model and LAP's you may be able to use EAP-TLS or EAP-PEAP; otherwise regardless of the WLC/LAP model, you can still use EAP-FAST. See the following guides for reference:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html?referring_site=RE&amp;amp;pos=3&amp;amp;page=https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 15:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-using-ise/m-p/4045076#M558848</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-12T15:56:24Z</dc:date>
    </item>
  </channel>
</rss>

