<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4424510#M568137</link>
    <description>&lt;P&gt;Typically your WLAN SSID is associated with a &lt;STRONG&gt;specific VLAN, &lt;/STRONG&gt;regardless of the wireless product.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco AireOS WLC with a specific Interface Group mapping to a VLAN:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 474px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123786iF258008ACDD1E198/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&amp;nbsp; &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 414px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123787iFB5DB23750E62FA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And in Meraki APs for a given SSID:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 448px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123788i957751F1835FAF74/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 00:04:41 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-06-28T00:04:41Z</dc:date>
    <item>
      <title>802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421052#M567962</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We’ve deployed Cisco ISE in our DC and we planned to control 802.1x wireless access from branch sites. We’ve already configured VPN tunnel between DC and Branches. &amp;nbsp;We would like to configure Dynamic VLAN assignment to the client PCs on branch sites, i.e., we’ve only one SSID and users from different user groups will be assigned to different VLAN when connected to Wi-Fi.&lt;/P&gt;&lt;P&gt;As we are using Meraki Wireless APs on branch sites, it is possible to use dynamic VLAN assignment feature with Cisco ISE?&lt;/P&gt;&lt;P&gt;As for now, we already configure dynamic VLAN feature in our environment, but some endpoints did not get IP assigned although it passed authentication and authorization.&lt;/P&gt;&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 10:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421052#M567962</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2021-06-21T10:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421076#M567963</link>
      <description>&lt;P&gt;I do not believe this solution works, since you have only 1 SSID, that is associated with VLAN aleady.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But with ISE profiling, based on the user Group you can setup the Security profile, what user / end device can access the resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;As for now, we already configure dynamic VLAN feature in our environment, but some endpoints did not get IP assigned although it passed authentication and authorization.&lt;/PRE&gt;
&lt;P&gt;is this wired or wireless ?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 11:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421076#M567963</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-21T11:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421119#M567965</link>
      <description>&lt;P&gt;Dynamic VLAN feature is supported with Cisco WLC right? But with Cisco Meraki , it cannot be work ?&lt;/P&gt;&lt;P&gt;But right now only some endpoints can't get IP address while most endpoints are working Ok. And there is no VLAN tagging enable for SSID at this moment.&lt;/P&gt;&lt;P&gt;We planned to enable 802.1x only for Wireless network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is not a proper solution , we'll deploy with different SSID then.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 13:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4421119#M567965</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2021-06-21T13:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4424510#M568137</link>
      <description>&lt;P&gt;Typically your WLAN SSID is associated with a &lt;STRONG&gt;specific VLAN, &lt;/STRONG&gt;regardless of the wireless product.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco AireOS WLC with a specific Interface Group mapping to a VLAN:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 474px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123786iF258008ACDD1E198/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&amp;nbsp; &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 414px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123787iFB5DB23750E62FA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And in Meraki APs for a given SSID:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 448px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/123788i957751F1835FAF74/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 00:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4424510#M568137</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-06-28T00:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4425856#M568222</link>
      <description>&lt;P&gt;Have you tried Group Policy with Filter ID or Airespace ACL?&lt;/P&gt;&lt;P&gt;Depends on your AuthZ conditions, you probably can assign different Group Policies to different AuthZ Profiles, each has different Group Policy associated with different VLAN ID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the docs for your reference.&amp;nbsp;&lt;A href="https://documentation.meraki.com/MR/Group_Policies_and_Block_Lists/Using_RADIUS_Attributes_to_Apply_Group_Policies" target="_self"&gt;https://documentation.meraki.com/MR/Group_Policies_and_Block_Lists/Using_RADIUS_Attributes_to_Apply_Group_Policies&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Creating_and_Applying_Group_Policies" target="_self"&gt;https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Creating_and_Applying_Group_Policies&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically you create the several Group Policies with different VLANs on Meraki Dashboard, then creat corresponding AuthZ Profiles on ISE which call the names of the Group Policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 05:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4425856#M568222</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2021-06-30T05:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Dynamic VLAN deployment for Cisco ISE and Meraki Access Points</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4425858#M568223</link>
      <description>&lt;P&gt;Looking for “Per User VLAN Tagging”&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/VLAN_Tagging" target="_self"&gt;https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/VLAN_Tagging&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 05:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-and-dynamic-vlan-deployment-for-cisco-ise-and-meraki/m-p/4425858#M568223</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2021-06-30T05:51:35Z</dc:date>
    </item>
  </channel>
</rss>

