<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stephen, thank you for in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645186#M138945</link>
    <description>&lt;P&gt;Stephen,&amp;nbsp;thank you for replying to my post.&lt;/P&gt;&lt;P&gt;Sorry for no replying soon, I wanted to tested first before replying.&amp;nbsp;I did map the WLAN to the local VLAN ID on an access point and it works,&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal is:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;corporate equipment will be assign to&amp;nbsp;&amp;nbsp;vlan 10&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;non-corporate equipment but AD user authentication is successful will be assign to vlan 11,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I wanted to accomplish all of this using one SSID and let ISE do the change of vlans&amp;nbsp;according to Authorization policies, but I can't figure it out how to do it. &amp;nbsp;When I the APs were in local mode, we used one single ssid "Employees" and ise put the employees in different subnet depending if it is corporate or not corporate devices. I was able to accomplish this by using two different authorization profiles in ISE that changes the&amp;nbsp;Airespace-Interface-Name = employee-noncorp for Non-corporate devices, and&amp;nbsp;Airespace-Interface-Name = employees for corporate devices. &amp;nbsp;Since we are using vlan mapping on the AP how will I go to accomplish this? I have been searching for some info on how to do this, but I couldn't find anything related to what I am trying to do.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2015 16:44:28 GMT</pubDate>
    <dc:creator>CSCO12400920</dc:creator>
    <dc:date>2015-02-06T16:44:28Z</dc:date>
    <item>
      <title>Flexconnect with ISE</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645184#M138943</link>
      <description>&lt;P&gt;Hi, I have a question. we are trying to implement flexconnect for our branch offices for the employee's WLAN, the guest WLAN will not be in flexconnect mode. My question is that my manager wants to have unique subnets for every branch in the Employee WLAN. By doing it this way I will have to create multiple Interfaces and tide it to the SSID per branch location. Is there other way around to do this without having to create multiple interfaces and WLANs?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645184#M138943</guid>
      <dc:creator>CSCO12400920</dc:creator>
      <dc:date>2021-07-05T09:24:11Z</dc:date>
    </item>
    <item>
      <title>You do not need to create an</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645185#M138944</link>
      <description>&lt;P&gt;You do not need to create an interface for each location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you do FlexConnect configurations, you map the WLAN to the local VLAN ID on a per AP basis.&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010001101.html#d35947e1465a1635&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2015 18:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645185#M138944</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2015-02-02T18:57:34Z</dc:date>
    </item>
    <item>
      <title>Stephen, thank you for</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645186#M138945</link>
      <description>&lt;P&gt;Stephen,&amp;nbsp;thank you for replying to my post.&lt;/P&gt;&lt;P&gt;Sorry for no replying soon, I wanted to tested first before replying.&amp;nbsp;I did map the WLAN to the local VLAN ID on an access point and it works,&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal is:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;corporate equipment will be assign to&amp;nbsp;&amp;nbsp;vlan 10&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;non-corporate equipment but AD user authentication is successful will be assign to vlan 11,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I wanted to accomplish all of this using one SSID and let ISE do the change of vlans&amp;nbsp;according to Authorization policies, but I can't figure it out how to do it. &amp;nbsp;When I the APs were in local mode, we used one single ssid "Employees" and ise put the employees in different subnet depending if it is corporate or not corporate devices. I was able to accomplish this by using two different authorization profiles in ISE that changes the&amp;nbsp;Airespace-Interface-Name = employee-noncorp for Non-corporate devices, and&amp;nbsp;Airespace-Interface-Name = employees for corporate devices. &amp;nbsp;Since we are using vlan mapping on the AP how will I go to accomplish this? I have been searching for some info on how to do this, but I couldn't find anything related to what I am trying to do.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 16:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645186#M138945</guid>
      <dc:creator>CSCO12400920</dc:creator>
      <dc:date>2015-02-06T16:44:28Z</dc:date>
    </item>
    <item>
      <title>Hey, it´s quite easy. You can</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645187#M138946</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it´s quite easy. You can use the AP-Groups in your Radius Request to assign different VLAN&amp;nbsp;per AP-Group per User Typ. That means in worst case two Radius Auth Policies per Branch. Good that we have rule based ;-).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Location A Corporate VLAN X&lt;/P&gt;&lt;P&gt;Location A non Corporate VLAN Y&lt;/P&gt;&lt;P&gt;Location B Corporate VLAN M&lt;/P&gt;&lt;P&gt;Location B non Corporate VLAN N&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14.399999618530273px;"&gt;From the&amp;nbsp;&lt;SPAN class="uicontrol" style="font-weight: bold;"&gt;Call Station ID Type&lt;/SPAN&gt;&amp;nbsp;drop-down list, choose the option that is sent to the RADIUS server in the Access-Request message. The following options are available:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14.399999618530273px;"&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_890D9606BDCA40EDB72035E01323DDF7"&gt;&lt;/A&gt;IP Address&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_102481ADBFBA470EBE2491F6FF0E2A5A"&gt;&lt;/A&gt;System MAC Address&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_851C06A53DCF411FBC0F09892D978A3C"&gt;&lt;/A&gt;AP MAC Address&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_62F03CCD89864ED883AD935AF3F5E9A3"&gt;&lt;/A&gt;AP MAC Address:SSID&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_006A930203244B93B8A62E2C1464A634"&gt;&lt;/A&gt;AP Name:SSID&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_9EB63ED39F1F4B04B9617BA90C2DB9ED"&gt;&lt;/A&gt;AP Name&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_832BD42B84EE43B19F7DA7C5BDD49A7B"&gt;&lt;/A&gt;AP Group&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_4BFBFB027EEF473F94226E5C631F49D2"&gt;&lt;/A&gt;Flex Group&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_EF911AF1663A46FB983AF9543F4051A2"&gt;&lt;/A&gt;AP Location&amp;nbsp;&lt;/LI&gt;&lt;LI style="margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;&lt;A name="ID214__choice_D189D960AA2F4EE5AAA346D11E29A32D"&gt;&lt;/A&gt;VLAN ID&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;TABLE class="olh_note" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; margin-top: 0.5em; margin-bottom: 1.25em; line-height: 14.399999618530273px; color: rgb(0, 0, 0);"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="td_faq" style="font-size: 1em; margin-top: 0em; margin-bottom: 0em; line-height: 1.2em; vertical-align: top;"&gt;&lt;B&gt;Note&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/B&gt;&lt;/TD&gt;&lt;TD class="td_faq" style="font-size: 1em; margin-top: 0em; margin-bottom: 0em; line-height: 1.2em; vertical-align: top;"&gt;&lt;P style="font-size: 1em; margin-top: 0.5em; margin-bottom: 0.5em; line-height: 1.2em;"&gt;The AP Name:SSID, AP Name, AP Group, Flex Group, AP Location, and VLAN ID options are added in the 7.4 release.&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_0101100.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And to set the VLAN ID use:&lt;/P&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;The RADIUS user attributes used for the VLAN ID assignment are:&amp;nbsp;&lt;/P&gt;&lt;UL style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;LI&gt;&lt;P&gt;IETF 64 (Tunnel Type)—Set this to VLAN.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;IETF 65 (Tunnel Medium Type)—Set this to 802&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;IETF 81 (Tunnel Private Group ID)—Set this to VLAN ID.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that is what you need......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Kind regards&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Philip&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;SPAN style="background-color: rgb(249, 249, 249);"&gt;--&amp;gt; Pls&amp;nbsp;rate useful responses &amp;lt;--&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 23:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-with-ise/m-p/2645187#M138946</guid>
      <dc:creator>Philip91</dc:creator>
      <dc:date>2015-02-09T23:26:14Z</dc:date>
    </item>
  </channel>
</rss>

