<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ibns 2.0 vlan-id in access-requests in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622464#M575139</link>
    <description>&lt;P&gt;See below for screenshot of packet capture on switch showing the vlan avp sent in access request to ISE - client was on vlan 110 (name STAFF_LAPTOP) which can be seen in the access request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll try this again with 16.12 on the switch to see if this is ios related - ISE was upgraded recently from 2.4 to 2.7 (upgrade was clean install with a restore)&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vlan attributes.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152541iE7B880B42883DE64/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vlan attributes.png" alt="vlan attributes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2022 11:20:52 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2022-06-01T11:20:52Z</dc:date>
    <item>
      <title>ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4619169#M575019</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm looking at an ibns 2 802.1x policy on Catalyst 3650 (ver 16.09.08) with ISE 2.7 patch 7. The switch setup should send the 802.1x client's vlan id to ISE (in the access-request during authentication) so that it can be used in an authorization condition.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got this working ok and can use the sent RADIUS attribute Tunnel-Private-Group-ID for authorisation. The problem I'm having is that ISE doesn't display this Tunnel-Private-Group-ID under "other attributes" in the authentication detail report. It does display the Tunnel-Type and Tunnel-Medium-Type attributes (see below) but not Tunnel-Private-Group-ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel-Type (tag=1) VLAN&lt;BR /&gt;Tunnel-Type (tag=2) VLAN&lt;BR /&gt;Tunnel-Medium-Type (tag=1) 802&lt;BR /&gt;Tunnel-Medium-Type (tag=2) 802&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone come across this before? As I said, the method works ok but I can't see the actual Tunnel-Private-Group-ID in the authentication reports which makes testing/monitoring a bit difficult.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 10:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4619169#M575019</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-05-27T10:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4619972#M575055</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/255857"&gt;@andrewswanson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just clarifying what exactly you're looking for (in the absence of any screenshots)&lt;/P&gt;
&lt;P&gt;When clicking on the Details of a successful Authentication, I can't see the VLAN ID listed in the "Authentication Details" part of the page, but further down the page I can see the RADIUS Attributes that are returned to the NAS - and VLAN is one of them&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="result.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152268i7FB5014600F8FBED/image-size/large?v=v2&amp;amp;px=999" role="button" title="result.png" alt="result.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or did you mean the reports under Operations &amp;gt; Reports &amp;gt;Reports &amp;gt; Endpoints and Users &amp;gt; RADIUS Authentications ?&lt;/P&gt;
&lt;P&gt;I don't see the VLAN (Tunnel-Private-Group-ID) listed there either - at best, I can see the Authorization Rule listed there (which, you could name such that, the VLAN_ID is included in the name for easier reference - e.g. CORP_VL1101 or whatever)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 20:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4619972#M575055</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-05-29T20:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4620290#M575061</link>
      <description>&lt;P&gt;Thanks for the response Arne.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the screenshot below for detail of successful authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VLAN isn't listed as it is in your screenshot. I can see Tunnel-Type and Tunnel-Medium-Type (both appear twice for some reason). Switch (Cat3650 16.09.08) config for sending vlan-id in access request is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-session attributes filter-list list radius-vlan&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;vlan-id&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;access-session authentication attributes filter-spec include list radius-vlan&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I add dhcp to the filter-list I can see these attributes ok in ISE (2.7 patch 7). The switch is sending the vlan-id and I can use Tunnel-Private-Group-ID in authz policy - I just can't see it in the authentication details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ies results.png" style="width: 875px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152314iA58D62298CD87288/image-size/large?v=v2&amp;amp;px=999" role="button" title="ies results.png" alt="ies results.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 08:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4620290#M575061</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-05-30T08:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4621918#M575117</link>
      <description>&lt;P&gt;&lt;SPAN class="user-badges-list"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Rising-star lia-component-message-view-widget-author-username"&gt;&lt;A id="link_18" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/255857" target="_self" aria-label="View Profile of andrewswanson"&gt;Andy&lt;/A&gt;&lt;/SPAN&gt;, it's curious to me that your endpoint authentication has two sets of VLANs. If possible, please let me know more about this endpoint.&lt;/P&gt;
&lt;P&gt;Also, do you mean the RADIUS auth is not sending VLAN info until dhcp also added to the filter-list?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 23:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4621918#M575117</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-05-31T23:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622071#M575130</link>
      <description>&lt;P&gt;Hi hslai&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the 2 sets of vlans listed for all endpoints (windows 10 (802.1x), phones (MAB) etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch filter-list (with just vlan-id) does send the vlan-id but ISE displays the 2 sets of vlans with no Tunnel-Private-Group-ID. When I add dhcp to the filter-list, the dhcp attributes are displayed correctly on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning to do a packet capture today to see exactly what the switch is sending to ISE in the filter-list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This behaviour is happening with all our 3650 stacks (16.9.4 and 16.9.8).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 06:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622071#M575130</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-06-01T06:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622464#M575139</link>
      <description>&lt;P&gt;See below for screenshot of packet capture on switch showing the vlan avp sent in access request to ISE - client was on vlan 110 (name STAFF_LAPTOP) which can be seen in the access request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll try this again with 16.12 on the switch to see if this is ios related - ISE was upgraded recently from 2.4 to 2.7 (upgrade was clean install with a restore)&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vlan attributes.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152541iE7B880B42883DE64/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vlan attributes.png" alt="vlan attributes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 11:20:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622464#M575139</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-06-01T11:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: ibns 2.0 vlan-id in access-requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622555#M575142</link>
      <description>&lt;P&gt;I'm having the same issue with 16.12.07. If I can find the time I'll contact TAC but its something I can live with for now.&lt;BR /&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 13:26:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-vlan-id-in-access-requests/m-p/4622555#M575142</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-06-01T13:26:42Z</dc:date>
    </item>
  </channel>
</rss>

