<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4888014#M1102813</link>
    <description>&lt;P&gt;Will check and update you max tomorrow&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 18:17:14 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-07-19T18:17:14Z</dc:date>
    <item>
      <title>Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887083#M1102729</link>
      <description>&lt;P&gt;We currently have Cisco 9300 switches and the devices connect via 802.1X authentication.&amp;nbsp; How can I configure Cisco switches where users can connect their laptops and it will put them in the correct VLAN automatically with 802.1X authentication.&amp;nbsp; I did some research online and the only option is VMPS but it is not compatible with Cisco 9300 switches.&amp;nbsp; Is there any other options or is there a separate device we can purchase?&amp;nbsp; Thank you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887083#M1102729</guid>
      <dc:creator>cooperrocks78</dc:creator>
      <dc:date>2023-07-18T15:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887090#M1102730</link>
      <description>&lt;P&gt;You could use Cisco ISE authorization profile feature to dynamically assign vlans as host or user authenticate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887090#M1102730</guid>
      <dc:creator>SDhaliwal</dc:creator>
      <dc:date>2023-07-18T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887098#M1102732</link>
      <description>&lt;P&gt;do you have AAA server ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887098#M1102732</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T15:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887115#M1102733</link>
      <description>&lt;P&gt;Yes, we have a RADIUS server for AAA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 16:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887115#M1102733</guid>
      <dc:creator>cooperrocks78</dc:creator>
      <dc:date>2023-07-18T16:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887116#M1102734</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/sec-ieee-8021x-vlan-assign.html" target="_blank"&gt;802.1X Authentication Services Configuration Guide, Cisco IOS XE Release 3SE (Catalyst 3850 Switches) - IEEE 802.1X VLAN Assignment [Support] - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;easy check this guide&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 16:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887116#M1102734</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-18T16:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887969#M1102807</link>
      <description>&lt;P&gt;What would be the difference in configuration on the Cisco side to allow users to connect on any port and i&lt;SPAN&gt;t will put them in the correct VLAN&lt;/SPAN&gt;?&amp;nbsp; On the NPC side, I am assuming to add each VLAN to a separate network policy and point to an AD group.&amp;nbsp; This is what my current 802.1x config looks like:&lt;/P&gt;&lt;P&gt;description ***USER/DATA 8021x***&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 60&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887969#M1102807</guid>
      <dc:creator>cooperrocks78</dc:creator>
      <dc:date>2023-07-19T17:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887971#M1102808</link>
      <description>&lt;P&gt;not all PC connect to port will get same VLAN, but each PC can get differ VLAN ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4887971#M1102808</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-19T17:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4888007#M1102812</link>
      <description>&lt;P&gt;correct, how would we accomplish this with RADIUS on a NPS server?&amp;nbsp; What would the config look like?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4888007#M1102812</guid>
      <dc:creator>cooperrocks78</dc:creator>
      <dc:date>2023-07-19T18:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4888014#M1102813</link>
      <description>&lt;P&gt;Will check and update you max tomorrow&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4888014#M1102813</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-19T18:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1X and Dynamic VLAN in Cisco 9300 Switches</title>
      <link>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4889958#M1102880</link>
      <description>&lt;P&gt;The port configuration remains the same, but the global configuration needs to have the "aaa authorization network &amp;lt;...&amp;gt;" command included.&lt;/P&gt;
&lt;P&gt;If the RADIUS server sends in the Access-Accept response the name or id of the vlan (as cisco-avpair attributes), the device will be put into the referenced vlan.&lt;BR /&gt;If the RADIUS server doesn't send this in the response packet, the device will be put into whatever is default configured on the port.&lt;/P&gt;
&lt;P&gt;There's some decent information in Cisco's guides regarding this, for example this one, with the radius attributes required mentioned there as well.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3650/sec-user-8021x-xe-3se-3650-book/sec-ieee-8021x-vlan-assign.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3650/sec-user-8021x-xe-3se-3650-book/sec-ieee-8021x-vlan-assign.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I've seen a few blogs describing this for NPS as well, but I don't have any links at hand right now.&lt;/P&gt;
&lt;P&gt;Now, depending on how big your environment is, and if you're starting to go into advanced 802.1x config like dynamic vlan assignment, I highly recommend looking into Cisco ISE as a part of the 802.1x deployment.&lt;BR /&gt;If nothing else, troubleshooting 802.1x authentications in ISE is a lot easier that doing so in NPS.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 22:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-802-1x-and-dynamic-vlan-in-cisco-9300-switches/m-p/4889958#M1102880</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2023-07-21T22:41:38Z</dc:date>
    </item>
  </channel>
</rss>

