<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-Access, VN with multiple IP pools in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4828953#M2310</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;if it's for specific SGT assignment u always can differentiate endpoint with specific attribute as belonging to specific ID-group :0)&lt;/P&gt;
&lt;P&gt;does it make sense for u in your case?&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 21:21:09 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2023-05-04T21:21:09Z</dc:date>
    <item>
      <title>SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539390#M1716</link>
      <description>&lt;P&gt;Hi colleagues,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering whether anyone has come across the following situation, related to migration of a standard LAN to SDA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the traditional LAN (typical 2-tier with L3 on the core and L2 downstream on the access) there could be multiple VLANS serving the same client types on different access-switches (worst case - a VLAN per access switch). Looking at the transition to SDA, and where we can't change existing used IPs, what are the options?&amp;nbsp; &amp;nbsp;Any thoughts pls?&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Guy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539390#M1716</guid>
      <dc:creator>GuyJCRaymakers40943</dc:creator>
      <dc:date>2022-01-26T15:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539451#M1717</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1092570"&gt;@GuyJCRaymakers40943&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This is a very typical request for migration where IP subnets must be both in and out of the fabric at the same time. I recommend having a look at the SD-Access Migration sessions in the Cisco Live On-Demand Library, specifically:&lt;/P&gt;
&lt;DIV class="catalog-result-title session-title rf-simple-flex-frame"&gt;
&lt;UL&gt;
&lt;LI class="title-text"&gt;Real World Route/Switch to Cisco SD-Access Migration Tools and Strategies - BRKCRS-3493 Event:&amp;nbsp;&lt;SPAN class="attribute-values" data-test="attribute-values"&gt;2020 Digital APJC&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="title-text"&gt;Updated Cisco SD-Access Migration Strategies - BRKENS-2008&amp;nbsp;&lt;SPAN class="attribute-name"&gt;Event:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="attribute-values" data-test="attribute-values"&gt;2021 Digital&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="title-text"&gt;Cisco SD-Access Integrating with Your Existing Network - BRKCRS-2812&amp;nbsp;&lt;SPAN class="attribute-name"&gt;Event:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="attribute-values" data-test="attribute-values"&gt;2020 Barcelona&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="catalog-result-title session-title rf-simple-flex-frame"&gt;
&lt;DIV class="title-text"&gt;&lt;SPAN&gt;As far as having multiple IP Pools in the same VN, that is not a problem at all. It has been supported since Day 1 of SDA.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="title-text"&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Cheers,&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Scott Hodgdon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Senior Technical Marketing Engineer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Enterprise Networking and Cloud Group&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 Jan 2022 16:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539451#M1717</guid>
      <dc:creator>Scott Hodgdon</dc:creator>
      <dc:date>2022-01-26T16:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539475#M1718</link>
      <description>&lt;P&gt;Thanks Scott,&lt;/P&gt;&lt;P&gt;Indeed - the multiple IP pools in a VN is OK - just having i.e. 10 IP pools for the same user community (example "employees"), not sure how to deal with that from an ISE policy point of view (authorization VLANs?). So perhaps this is more an ISE question than SD-Access...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll take a look at the listed CL sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Guy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 16:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539475#M1718</guid>
      <dc:creator>GuyJCRaymakers40943</dc:creator>
      <dc:date>2022-01-26T16:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539527#M1719</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1092570"&gt;@GuyJCRaymakers40943&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Yes, ISE will assign a VLAN based on the authentication result and then that VLAN is mapped to a VN (aka VRF) on the SVI.&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Cheers,&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Scott Hodgdon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Senior Technical Marketing Engineer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Enterprise Networking and Cloud Group&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 17:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539527#M1719</guid>
      <dc:creator>Scott Hodgdon</dc:creator>
      <dc:date>2022-01-26T17:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539998#M1720</link>
      <description>&lt;P&gt;Hi Scot,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Indeed - so in the scenario where you end up, in SDA (not traditional networking), with multiple VLANS for the same user community within the same VN - how do you craft the ISE policy so that users are shared across these multiple vlans after they authenticated?&amp;nbsp; &amp;nbsp;That's really the scenario i'm looking into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;user "employees" and I have vlan names employee_1, employee_2, employee_3, employee_4, etc..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Guy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 06:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4539998#M1720</guid>
      <dc:creator>GuyJCRaymakers40943</dc:creator>
      <dc:date>2022-01-27T06:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540049#M1721</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1092570"&gt;@GuyJCRaymakers40943&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;In ISE there will be policy sets that will assign a VLAN based on the authentication / authorization information or perhaps even device profiling (or both). So perhaps the VN "Employees" has VLANs for HR, Sales, Engineering, Finance, IT, etc, and the employees in those groups are assigned to those VLANs when they are authenticated by ISE.&lt;/P&gt;
&lt;P&gt;Have a look at the Policy Sets chapter at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_segmentation.html#ID37" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_segmentation.html#ID37&lt;/A&gt;&amp;nbsp;. If you can get yoru hands on a a demo ISE in dcloud.cisco.com or developer.cisco.com (see the sandboxes), then that will help you look at the GUI to better understand what is being discussed in the admin guide.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Cheers,&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Scott Hodgdon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Senior Technical Marketing Engineer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Enterprise Networking and Cloud Group&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 08:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540049#M1721</guid>
      <dc:creator>Scott Hodgdon</dc:creator>
      <dc:date>2022-01-27T08:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540093#M1722</link>
      <description>&lt;P&gt;Thanks Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me add one more layer - in my example assume all users are Engineering and they need to get "distributed" across these multiple vlans (on SDA). How would we do that in ISE?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Guy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 08:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540093#M1722</guid>
      <dc:creator>GuyJCRaymakers40943</dc:creator>
      <dc:date>2022-01-27T08:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540200#M1723</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1092570"&gt;@GuyJCRaymakers40943&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I do not know the inner workings of ISE (not my area of focus), so you may want to follow up with this in the ISE community. That said, the way I believe it works is to add user/device profiles to specific groups in ISE and then those groups are associated with specific policy sets.&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Cheers,&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Scott Hodgdon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Senior Technical Marketing Engineer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s3"&gt;Enterprise Networking and Cloud Group&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 11:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4540200#M1723</guid>
      <dc:creator>Scott Hodgdon</dc:creator>
      <dc:date>2022-01-27T11:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4545097#M1742</link>
      <description>&lt;P&gt;Hi Guy&lt;/P&gt;&lt;P&gt;You can archive that one by putting the switches into different location groups. You also have to define different AuthZ Result with the different Vlan assigned.&lt;/P&gt;&lt;P&gt;Then you can make policy sets based on the location of the switches.&lt;/P&gt;&lt;P&gt;For example if Engineer A connected to Switch in Location A he gets Engineer-VLAN-A assigned.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 20:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4545097#M1742</guid>
      <dc:creator>markus.forrer</dc:creator>
      <dc:date>2022-02-03T20:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: SD-Access, VN with multiple IP pools</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4828953#M2310</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;if it's for specific SGT assignment u always can differentiate endpoint with specific attribute as belonging to specific ID-group :0)&lt;/P&gt;
&lt;P&gt;does it make sense for u in your case?&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 21:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-vn-with-multiple-ip-pools/m-p/4828953#M2310</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-05-04T21:21:09Z</dc:date>
    </item>
  </channel>
</rss>

