<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Proxy - Restricting Dynamic VLAN Assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4722609#M578293</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;When relying on an external proxy server for the return VLAN (as they have the identity information for the authorisation policy) is there any way we can define on ISE what VLANs they are actually allowed to return?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this could be a security issue if we are trusting external proxy servers to return dynamic VLAN information. Any idea?&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;KT&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 17:28:02 GMT</pubDate>
    <dc:creator>KatherineTran</dc:creator>
    <dc:date>2022-11-16T17:28:02Z</dc:date>
    <item>
      <title>Radius Proxy - Restricting Dynamic VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4722609#M578293</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;When relying on an external proxy server for the return VLAN (as they have the identity information for the authorisation policy) is there any way we can define on ISE what VLANs they are actually allowed to return?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this could be a security issue if we are trusting external proxy servers to return dynamic VLAN information. Any idea?&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;KT&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 17:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4722609#M578293</guid>
      <dc:creator>KatherineTran</dc:creator>
      <dc:date>2022-11-16T17:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Proxy - Restricting Dynamic VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4722747#M578299</link>
      <description>&lt;P&gt;The only option I can think of that might work would be to enable the "On Access-Accept, continue to Authorization Policy" option in your RADIUS Server Sequence &amp;gt; Advanced Attribute Settings to let ISE perform Authorization.&lt;BR /&gt;You would then create AuthZ Policies with a matching condition like 'Radius·Tunnel-Private-Group-ID EQUALS &amp;lt;id/name&amp;gt;' with a resulting AuthZ Profile that sends the same VLAN in the response. If none of the defined AuthZ Policies in ISE are matched, it will respond with an Access-Reject.&lt;/P&gt;
&lt;P&gt;I don't know if this will work, so you would need to test it in your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 21:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4722747#M578299</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-11-16T21:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Proxy - Restricting Dynamic VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4723305#M578309</link>
      <description>&lt;P&gt;Thanks for the response. Unfortunately, we need the authorisation policy to be returned by the external RADIUS server as it has the identity information. From my googling - I don't think it's possible on ISE!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 16:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4723305#M578309</guid>
      <dc:creator>KatherineTran</dc:creator>
      <dc:date>2022-11-17T16:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Proxy - Restricting Dynamic VLAN Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4724421#M578380</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1310935"&gt;@KatherineTran&lt;/a&gt;, You are correct. VLAN is a tagged attribute and that is not being handled by what Greg described.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 01:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-proxy-restricting-dynamic-vlan-assignment/m-p/4724421#M578380</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-20T01:17:30Z</dc:date>
    </item>
  </channel>
</rss>

