<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP type-based dynamic VLAN assignment for wireless client in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239489#M279095</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1574309"&gt;@Roman Yu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;On the WLC the only configurarion required is "AAA overide" on the WLAN.&amp;nbsp; And create the appropriate vlans. All the rest is Radius job.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Dec 2024 19:27:31 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2024-12-20T19:27:31Z</dc:date>
    <item>
      <title>EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239484#M279092</link>
      <description>&lt;P&gt;Hello everyone. I want to place a wireless user in one VLAN or another, depending on the type of authentication, EAP-TLS or PEAP. How do I do this in the wireless part of the network?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 19:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239484#M279092</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-20T19:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239489#M279095</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1574309"&gt;@Roman Yu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;On the WLC the only configurarion required is "AAA overide" on the WLAN.&amp;nbsp; And create the appropriate vlans. All the rest is Radius job.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 19:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239489#M279095</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-20T19:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239494#M279097</link>
      <description>&lt;P&gt;You use ISE?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 19:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239494#M279097</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-20T19:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239507#M279100</link>
      <description>&lt;P&gt;Thank you Flavio!&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="6:5"&gt;But what&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="12:9"&gt;interface&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="22:3"&gt;or&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="26:6"&gt;group&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="33:11"&gt;interfaces&lt;/SPAN&gt;&lt;SPAN&gt; should I &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="45:9"&gt;assign&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="55:7"&gt;this&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="63:4"&gt;WLAN&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="67:1"&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;And w&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="0:3"&gt;hy&lt;/SPAN&gt; should we &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="9:9"&gt;assign&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="19:12"&gt;specific&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="32:4"&gt;VLAN&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c-32.png" border="0" width="616" height="318" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239507#M279100</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-20T21:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239508#M279101</link>
      <description>&lt;P&gt;Yes, we do.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239508#M279101</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-20T21:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239509#M279102</link>
      <description>&lt;P&gt;The WLC needs to know which vlan it will put the client.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 id="toc-hId-27233197"&gt;"Step 2. Configure the VLANs&lt;/H4&gt;
&lt;P&gt;This procedure explains how to configure VLANs on the Catalyst 9800 WLC. As explained earlier in this document, &lt;STRONG&gt;the VLAN ID specified under the Tunnel-Private-Group ID attribute of the RADIUS server must also exist in the WLC.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the example, the user smith-102 is specified with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="cCN_CmdName"&gt;&lt;STRONG&gt;Tunnel-Private-Group ID of 102 (VLAN =102)&lt;/STRONG&gt;&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the RADIUS server."&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239509#M279102</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-20T21:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239510#M279103</link>
      <description>&lt;P&gt;Then add two policy set one for eap-tls and other for peap.&lt;/P&gt;
&lt;P&gt;In these policy set use allow protocol to set eap-tls or peap.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In authc and authz condition use match eap-tls or peap.&lt;/P&gt;
&lt;P&gt;In authz use authz policy accept set attribute vlan value.&lt;/P&gt;
&lt;P&gt;this example below how you can use PEAP as condition in authc and authz&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sendthepayload.com/configuring-an-802-1x-wired-policy-using-peap-mschapv2-wo-mar/" target="_blank"&gt;https://sendthepayload.com/configuring-an-802-1x-wired-policy-using-peap-mschapv2-wo-mar/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239510#M279103</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-20T21:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239667#M279120</link>
      <description>&lt;P&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="0:7"&gt;Colleagues&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="7:1"&gt;,&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="9:2"&gt;you&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="12:4"&gt;were&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="17:5"&gt;right&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="22:1"&gt;.&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="24:1"&gt;I&lt;/SPAN&gt;&lt;SPAN&gt;'ve &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="26:6"&gt;created&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="33:7"&gt;profiles&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="40:1"&gt;,&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="42:8"&gt;policies&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="51:1"&gt;and etc&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="59:1"&gt;.&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="61:8"&gt;Assigned&lt;/SPAN&gt;&lt;SPAN&gt; an &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="96:11"&gt;interface&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="89:6"&gt;group&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="70:3"&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="74:9"&gt;test&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="84:4"&gt;WLAN&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="107:1"&gt;.&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="109:3"&gt;Everything&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="113:8"&gt;works!&lt;/SPAN&gt;&lt;SPAN&gt; It &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="132:11"&gt;distributes&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="123:8"&gt;clients&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="144:2"&gt;the&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="147:6"&gt;required&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="154:4"&gt;VLANs depending on EAP-TLS or PEAP&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="158:1"&gt;.&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="160:3"&gt;I&lt;/SPAN&gt; &lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="164:8"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt; it&lt;/SPAN&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="172:1"&gt;! &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 16:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239667#M279120</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-21T16:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239671#M279121</link>
      <description>&lt;P&gt;Did you match condition as I suggest?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 16:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239671#M279121</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-21T16:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239677#M279122</link>
      <description>&lt;P&gt;On the test laptop, I found that it had fallen off the Active Directory domain and cannot pass machine authentication. But if I disable the machine's domain membership in the Authorization Policy, then this problematic laptop successfully connects to the network. I thought that EAP-TLS requires checking the machine first, then the user, and there is no way to change this protocol behavior.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 16:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239677#M279122</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-21T16:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239678#M279123</link>
      <description>&lt;P&gt;Yes, exactly.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2024 16:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5239678#M279123</guid>
      <dc:creator>Roman Yu</dc:creator>
      <dc:date>2024-12-21T16:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: EAP type-based dynamic VLAN assignment for wireless client</title>
      <link>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5240031#M279145</link>
      <description>&lt;P&gt;EAP-TLS authenticates whatever you setup oin the wireless profile.&lt;/P&gt;
&lt;P&gt;For Windows, by default, it is machine authentication only, but if you change it to User OR Machine it will do Machine cert first on the login screen, and then it will re-authenitcate using the User cert after successful log in.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 10:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-type-based-dynamic-vlan-assignment-for-wireless-client/m-p/5240031#M279145</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-12-23T10:56:46Z</dc:date>
    </item>
  </channel>
</rss>

