<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VLAN Steering and MAB authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640886#M243786</link>
    <description>&lt;P&gt;iPSK might help you if you want encryption:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jun 2022 14:56:22 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2022-06-29T14:56:22Z</dc:date>
    <item>
      <title>VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640494#M243759</link>
      <description>&lt;P&gt;This question relates to a network of 9130 APs, managed by a 9800 WLC. I'm&amp;nbsp; trying to reduce the number of SSIDs being used in the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the reasons for having so many SSIDs is that there are several communities of wireless IoT devices that have no 802.1x capability, so must be authenticated using MAB. That would be fine, if all IoT devices needed to go into the same VLAN. However, there are families of devices, each one needing to be handled differently, so they are put I to different SSIDs/WLANs/VLANS, hence the high SSID count.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to use the ISE that handles 802.1x to do VLAN steering, so that I could use the same SSID, then steer client devices into different VLANs based upon their MAC address. I've&amp;nbsp; read about doing this with something called MyDevice Portal, but I haven't&amp;nbsp; found details on this, or if it's possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone say if what I propose is possible, and if so, point me at some documentation that will get me started&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 21:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640494#M243759</guid>
      <dc:creator>Jim Blake</dc:creator>
      <dc:date>2022-06-28T21:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640510#M243761</link>
      <description>&lt;P&gt;You can create profiles based on that you can give access permission: you can use vendor OUI (when you use MAB authentication)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 21:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640510#M243761</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-28T21:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640539#M243763</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;From the ISE side your challange is to identify the device you want to spread on the vlans. You can work with profile. On the WLC side, you need to enable "Allow AAA Override" on the WLC, advanced tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;On the AP group, instead poniting the WLAN to a interface group, you need to point to a non-routable interface.&amp;nbsp; But, you need to add the vlan on the WLC under "CONTROLLER" and Interfaces.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 22:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640539#M243763</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-06-28T22:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640886#M243786</link>
      <description>&lt;P&gt;iPSK might help you if you want encryption:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 14:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640886#M243786</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-06-29T14:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640947#M243790</link>
      <description>&lt;P&gt;The IoT devices have no 802.1x supplicant, but lets assume they could handle iPSK. Can the ISE do VLAN steering based upon each different user/group's PSK? If that were possible, that could be a simple solution&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 16:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640947#M243790</guid>
      <dc:creator>Jim Blake</dc:creator>
      <dc:date>2022-06-29T16:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640952#M243792</link>
      <description>&lt;P&gt;That looks to be the way to go...I will lab it and see how it works. Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 20:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4640952#M243792</guid>
      <dc:creator>Jim Blake</dc:creator>
      <dc:date>2022-07-03T20:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Steering and MAB authentication</title>
      <link>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4641324#M243815</link>
      <description>&lt;P&gt;Yeah this is exactly what this could be used for, as long as the IoT device is capable of WPA2/AES with a PSK.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It takes some additional ISE configuration though, because you need to create a profile for each VLAN you want to assign.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my opinion it would probably be better to put them all into the same VLAN and make sure that this VLAN is correctly isolated.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 06:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-steering-and-mab-authentication/m-p/4641324#M243815</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-06-30T06:41:44Z</dc:date>
    </item>
  </channel>
</rss>

