<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  I do not get exactly what in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491506#M87404</link>
    <description>&lt;P&gt;&amp;nbsp;I do not get exactly what are you looking for.. But still&lt;/P&gt;&lt;P&gt;The&amp;nbsp; two kind of access you are anticipating can be achived by either way&lt;/P&gt;&lt;P&gt;Chage of VLAN : as explained by you... you need to create two differnent authorization policies as per&amp;nbsp; users belongs&amp;nbsp; to (AD )group &amp;lt;e.g. employee or guest..&amp;gt; ..&lt;/P&gt;&lt;P&gt;dACL : You can push downloadable Acl to switch as per user membership to AD.&lt;/P&gt;&lt;P&gt;Let me know if you need help from design or configuration&amp;nbsp; point of view...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2014 21:39:09 GMT</pubDate>
    <dc:creator>Parag Mahajan</dc:creator>
    <dc:date>2014-03-10T21:39:09Z</dc:date>
    <item>
      <title>Using ISE to dynamically VLAN change</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491505#M87402</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I need some help to dynamically change VLAN on each port of my Catalyst 3560, to do this, I don't want to use the MAC address filtering but I want to use conditions already in place in my ISE to switch port between two VLAN (Guest and Corporate) where one give access to the corporate LAN and the other to Internet without LAN access.&lt;/P&gt;&lt;P&gt;Maybe someone of you had could have some ideas to do this with the use, or maybe without VLAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS : Sorry for my bad English, i'm not a native English speaker &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491505#M87402</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2019-03-11T04:30:47Z</dc:date>
    </item>
    <item>
      <title> I do not get exactly what</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491506#M87404</link>
      <description>&lt;P&gt;&amp;nbsp;I do not get exactly what are you looking for.. But still&lt;/P&gt;&lt;P&gt;The&amp;nbsp; two kind of access you are anticipating can be achived by either way&lt;/P&gt;&lt;P&gt;Chage of VLAN : as explained by you... you need to create two differnent authorization policies as per&amp;nbsp; users belongs&amp;nbsp; to (AD )group &amp;lt;e.g. employee or guest..&amp;gt; ..&lt;/P&gt;&lt;P&gt;dACL : You can push downloadable Acl to switch as per user membership to AD.&lt;/P&gt;&lt;P&gt;Let me know if you need help from design or configuration&amp;nbsp; point of view...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 21:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491506#M87404</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2014-03-10T21:39:09Z</dc:date>
    </item>
    <item>
      <title>You can apply a VLAN change</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491507#M87406</link>
      <description>&lt;P&gt;You can apply a VLAN change at any of your authorization profiles. Just keep in mind that devices without a supplicant (printers, cameras, etc) are not a good candidate as they might not know that you changed their VLAN, thus, they will not request a new IP address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that being said, you can use dACLs to restrict access. You can refer to the following document:http://www.cisco.com/c/dam/en/us/td/docs/security/ise/how_to/HowTo-41-Guest_Services.pdf&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 04:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491507#M87406</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-03-11T04:50:05Z</dc:date>
    </item>
    <item>
      <title>Well you can easyly</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491508#M87408</link>
      <description>&lt;P&gt;Well you can easyly accomplish this with ISE and push the DACL based on the user authnetication and since you only want when user is unable to authenticate then he should be given guest vlan and other wise corporate vlan but i would suggest do check cisco ISE guest services feature its exaclty what you want to deply and more.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Do check cisco how to guides to exact step by step configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 12:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491508#M87408</guid>
      <dc:creator>kaaftab</dc:creator>
      <dc:date>2014-03-11T12:50:05Z</dc:date>
    </item>
    <item>
      <title>Well you can easyly</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491509#M87411</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 12:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491509#M87411</guid>
      <dc:creator>kaaftab</dc:creator>
      <dc:date>2014-03-11T12:50:52Z</dc:date>
    </item>
    <item>
      <title>Well you can easyly</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491510#M87413</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 12:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491510#M87413</guid>
      <dc:creator>kaaftab</dc:creator>
      <dc:date>2014-03-11T12:53:57Z</dc:date>
    </item>
    <item>
      <title>Thanks for your answer, I</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491511#M87416</link>
      <description>&lt;P&gt;Thanks for your answer, I also saw this morning the possibility to use this command : "&amp;nbsp;authentication event fail action authorize vlan &amp;lt;my_guest_VLAN&amp;gt;" but it actually doesn' work. I'm very interrested about dACL but I don't understand how can it make switch either VLAN Corp. or VLAN Guest each port of my 3560. I will see in this direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491511#M87416</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2014-03-11T13:14:40Z</dc:date>
    </item>
    <item>
      <title>Thanks for your answer.The</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491512#M87420</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;The aim is to "detect" if the device is a corporate device and if is not, it will be automatically put in VLAN Guest. The user can't log in Web Portal or other, it's just the profiling of the device which determine his VLAN assignment.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-to-dynamically-vlan-change/m-p/2491512#M87420</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2014-03-11T13:18:50Z</dc:date>
    </item>
  </channel>
</rss>

