<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.2 MAC authentication and dynamic vlan assignment in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679447#M140022</link>
    <description>&lt;P&gt;Is this possible to do with ACS 4.2? Is there a suitable document on this? There is no access to NAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 10:39:07 GMT</pubDate>
    <dc:creator>codflanglers</dc:creator>
    <dc:date>2021-07-05T10:39:07Z</dc:date>
    <item>
      <title>ACS 4.2 MAC authentication and dynamic vlan assignment</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679447#M140022</link>
      <description>&lt;P&gt;Is this possible to do with ACS 4.2? Is there a suitable document on this? There is no access to NAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679447#M140022</guid>
      <dc:creator>codflanglers</dc:creator>
      <dc:date>2021-07-05T10:39:07Z</dc:date>
    </item>
    <item>
      <title>yes it's very so much quite</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679448#M140023</link>
      <description>&lt;P&gt;yes it's very so much quite possible ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++see below Doc :&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/configuration/guide/acs42_config_guide/nac_conf.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;read "Configure Radius Authorization Components"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;these are the three attributes need to be configured for vlan ID override :&lt;/P&gt;&lt;P&gt;•Tunnel-Type (attribute 64)—Specifies the type of tunnel that is set up for the user to connect. In the sample RACs, this value is set to type 10, VLAN, which indicates that the user is granted access to a VLAN that is configured on the switch.&lt;/P&gt;&lt;P&gt;•Tunnel-Medium-Type (attribute 65)—Indicates which protocol to use over the tunnel. In the sample RACs, this is set to type 6, which specifies an 802 protocol. In the NAC/NAP environment, this is the 802.1x protocol.&lt;/P&gt;&lt;P&gt;•Tunnel-Private-Group-ID (attribute 81)—Indicates the group ID for the VLAN tunnel. In the sample RAC, this is set to Quarantine, which denotes a quarantine VLAN to which devices are assigned. In actual practice, you should set this value to a value that is configured on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;+++on the WLC enable MAC filtering and aaa override on the WLAN,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++add the MAC address on the radius server as username and password ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 18:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679448#M140023</guid>
      <dc:creator>ali aqrabawi</dc:creator>
      <dc:date>2015-07-28T18:49:02Z</dc:date>
    </item>
    <item>
      <title>Please refer to the below</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679449#M140024</link>
      <description>&lt;P&gt;Please refer to the below link :&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/security/secure-acs-4-2-windows/model.html#~tab-documents&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 22:08:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679449#M140024</guid>
      <dc:creator>sobhardw</dc:creator>
      <dc:date>2015-07-28T22:08:12Z</dc:date>
    </item>
    <item>
      <title>Many hosts that ACS</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679450#M140025</link>
      <description>&lt;P class="pB1_Body1"&gt;Many hosts that ACS authenticates run agent software that requests access to network resources and receives authorization from ACS. However, some hosts do not run agent software. For example:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1010534" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;Many 802.1x port security deployments authenticate hosts that do not have appropriate security agent software, such as Cisco Trust Agent.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1010535" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;When an agentless host is connected to a Layer 2 device and an Extensible Authentication Protocol over User Datagram Protocol timeout (EoU timeout) occurs, in-band posture validation cannot occur.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1010536" style="text-decoration: none;"&gt;&lt;/A&gt; &lt;A name="wpmkr1022943" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;ACS solves this problem by using the MAC address of the host device to identify and authenticate the host. This technique is called MAC authentication bypass (MAB).&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/configuration/guide/acs42_config_guide/noagent.html#wp1010943"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/configuration/guide/acs42_config_guide/noagent.html#wp1010943&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 09:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679450#M140025</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2015-08-04T09:43:15Z</dc:date>
    </item>
    <item>
      <title> Configure ACS for Dynamic</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679451#M140026</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&amp;nbsp;Configure ACS for Dynamic VLAN Assignment&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Dynamic VLAN assignment is one feature that places a wireless user into a specific VLAN based on the credentials supplied by the user. This task of assigning users to a specific VLAN is handled by a RADIUS authentication server, such as Cisco Secure ACS. This can be used, for example, to allow the wireless host to remain on the same VLAN as it moves within a campus network.&lt;/P&gt;&lt;P&gt;Please refer the below link for the complete configuration guide .&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/99121-vlan-acs-ad-config.html&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 13:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-mac-authentication-and-dynamic-vlan-assignment/m-p/2679451#M140026</guid>
      <dc:creator>Prakash Parvathala</dc:creator>
      <dc:date>2015-08-04T13:29:23Z</dc:date>
    </item>
  </channel>
</rss>

