<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vlan precedence in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906195#M583449</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1491290"&gt;@ramziabdelhak&lt;/a&gt; you should modify your ISE authorisation rules to not push down the VLAN to the switch as this takes presedence over the statically assigned VLAN.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2023 09:10:45 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-08-16T09:10:45Z</dc:date>
    <item>
      <title>Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906190#M583448</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On a C9300L switch, i have interface with ISE Dot 1 x configuration, what i want is that the statically assigned vlan using " switchport Access vlan XX" takes precedence over the vlan pushed by the ISE after a succesfull authentication,&lt;/P&gt;&lt;P&gt;For now, the ISE assigned vlan takes effect,&lt;/P&gt;&lt;P&gt;is there a solution ?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 09:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906190#M583448</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-08-16T09:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906195#M583449</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1491290"&gt;@ramziabdelhak&lt;/a&gt; you should modify your ISE authorisation rules to not push down the VLAN to the switch as this takes presedence over the statically assigned VLAN.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 09:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906195#M583449</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-16T09:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906197#M583450</link>
      <description>&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;But this type of configuration has already worked with 3750 Switch serie, do you it&amp;nbsp; is purhaps a deprectated behaviour ?&lt;/P&gt;&lt;P&gt;Thnks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 09:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906197#M583450</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-08-16T09:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906218#M583454</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1491290"&gt;@ramziabdelhak&lt;/a&gt; sorry, not sure, that's not my experience.&lt;/P&gt;
&lt;P&gt;Why do you need to send a dynamic VLAN assignment if you do not wish to use it? You can modify your ISE authorisation rules to send (or not send) a dynamic VLAN depending on the NAD group, connected user etc.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 09:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906218#M583454</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-16T09:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906222#M583456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the ISE, there a bunch of policies that apply to hundreds of users, and only 20-30 of them needs a special vlan; so instead of creating a new policy for them, we assign it statically on there interfaces.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 10:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906222#M583456</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-08-16T10:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906227#M583457</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1491290"&gt;@ramziabdelhak&lt;/a&gt; sure ok, create a group (or a couple of groups) for those 20-30 users, create an new authorisation rule(s) above the existing rule(s) and match against the group of users and push the dynamic VLAN. Then on the existing rules remove the dynamic VLAN.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 10:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906227#M583457</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-16T10:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906253#M583458</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you, i think it is a more scalabale solution,&lt;/P&gt;&lt;P&gt;Nevertheless, i realy want to know why this behavious was once supported by the 3750x,&lt;/P&gt;&lt;P&gt;Thanks again Rob&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 11:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906253#M583458</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-08-16T11:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906860#M583470</link>
      <description>&lt;P&gt;Probably the dynamic VLAN will not be applied on this switch if the&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;aaa authorization network ... group RADIUSxxxx&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;command is removed. But it may have other effects.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4906860#M583470</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2023-08-17T07:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan precedence</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4907105#M583489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285490"&gt;@Peter Koltl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That would not be possible since removing this command will desable AAA authorization on the switch as a whole,&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 14:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-precedence/m-p/4907105#M583489</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-08-17T14:50:03Z</dc:date>
    </item>
  </channel>
</rss>

