<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Flexconnect  local switching using dynamic vlan assignment with ISE and MDM in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-local-switching-using-dynamic-vlan-assignment-with/m-p/2790300#M67249</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I am looking for advice on how to configure a WLC to use dynamic VLAN assignment when the access points are in flexconnect with local switching.&lt;/P&gt;
&lt;P&gt;We have a central 8510 and APs at several remote locations. Each AP is trunked locally at the site to a switch with a native VLAN for AP management and a 2nd VLAN for the corporate SSID. At the moment only these 2 VLANs are allowed over the trunk.&lt;/P&gt;
&lt;P&gt;We have an ISE used for client authN and authZ on the WLAN&lt;/P&gt;
&lt;P&gt;As it stands all corporate access works OK&lt;/P&gt;
&lt;P&gt;We also have an external MDM server for allowing BYOD to access the network assuming they pass registration status &amp;amp; compliance checks defined on the MDM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I am trying to work out is how to configure is how to set up the WLC so that if a new client associates with the corporate SSID and is registered on the external MDM server but fails the compliance check. In this scenario I want to move the client into a quarantine VLAN and only allow access to defined IP addresses to allow it to download any patches needed to pass the compliance check.&lt;/P&gt;
&lt;P&gt;Has anyone set up a WLC in this mode before ?&lt;/P&gt;
&lt;P&gt;If so what needs to be done on the WLC, the AP trunk port, flexconnect groups etc&lt;/P&gt;
&lt;P&gt;I cant see how to map the quarantine VLAN to the corporate SSID so that the ISE can force a CoA and move the client into the quarantine VLAN from the compliant VLAN&lt;/P&gt;
&lt;P&gt;Any help much appreciated&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Martyn&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 11:31:56 GMT</pubDate>
    <dc:creator>martaylor</dc:creator>
    <dc:date>2021-07-05T11:31:56Z</dc:date>
    <item>
      <title>Flexconnect  local switching using dynamic vlan assignment with ISE and MDM</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-switching-using-dynamic-vlan-assignment-with/m-p/2790300#M67249</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I am looking for advice on how to configure a WLC to use dynamic VLAN assignment when the access points are in flexconnect with local switching.&lt;/P&gt;
&lt;P&gt;We have a central 8510 and APs at several remote locations. Each AP is trunked locally at the site to a switch with a native VLAN for AP management and a 2nd VLAN for the corporate SSID. At the moment only these 2 VLANs are allowed over the trunk.&lt;/P&gt;
&lt;P&gt;We have an ISE used for client authN and authZ on the WLAN&lt;/P&gt;
&lt;P&gt;As it stands all corporate access works OK&lt;/P&gt;
&lt;P&gt;We also have an external MDM server for allowing BYOD to access the network assuming they pass registration status &amp;amp; compliance checks defined on the MDM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I am trying to work out is how to configure is how to set up the WLC so that if a new client associates with the corporate SSID and is registered on the external MDM server but fails the compliance check. In this scenario I want to move the client into a quarantine VLAN and only allow access to defined IP addresses to allow it to download any patches needed to pass the compliance check.&lt;/P&gt;
&lt;P&gt;Has anyone set up a WLC in this mode before ?&lt;/P&gt;
&lt;P&gt;If so what needs to be done on the WLC, the AP trunk port, flexconnect groups etc&lt;/P&gt;
&lt;P&gt;I cant see how to map the quarantine VLAN to the corporate SSID so that the ISE can force a CoA and move the client into the quarantine VLAN from the compliant VLAN&lt;/P&gt;
&lt;P&gt;Any help much appreciated&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Martyn&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-switching-using-dynamic-vlan-assignment-with/m-p/2790300#M67249</guid>
      <dc:creator>martaylor</dc:creator>
      <dc:date>2021-07-05T11:31:56Z</dc:date>
    </item>
  </channel>
</rss>

