cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
377
Views
1
Helpful
3
Replies

ISE policies for SDA with FZ - Re-use pool names or vlan ids

s.van
Level 1
Level 1

Hi 

I have a new SDA brownfield deployment, which needs to retain the old ip pools. I was looking at FZs to accommodate this requirement.(vlan/ip pools per floor) however with this the ise policy lines are growing exponentially.

The authz policies look something like...

"If my NAD source is in Fabric Zone 1 and my user is a corporate user then the result will be 10_10_10_0-VN1"

"If my NAD source is in Fabric Zone 2 and my user is a corporate user then the result will be 10_10_11_0-VN1"

"If my NAD source is in Fabric Zone 3 and my user is a corporate user then the result will be 10_10_12_0-VN1"

"If my NAD source is in Fabric Zone 4 and my user is a corporate user then the result will be 10_10_13_0-VN1"

"If my NAD source is in Fabric Zone 5 and my user is a corporate user then the result will be 10_10_14_0-VN1"

 and the list grows exponentially if i add a new Fabric site and it becomes a nightmare to manage the policies.

The challenge is that i'm unable to reuse vlanIDs/Names across FZs in the same fabric.(or another feature from cisco which can do it )

Is there a better way to do this ?

Thanks

3 Replies 3

jedolphi
Cisco Employee
Cisco Employee

Ability to assign same VLAN name to different IP range per-FZ has been written into the SD-Access code but unfortunately is not generally available yet. If you can wait a few months for the code change then please ask your Cisco sales representative to contact me and we can coordinate scheduling. In the short term you could manually deploy VLAN groups, please note this has the potential to be quite manual. https://community.cisco.com/t5/identity-services-engine-ise/best-practice-for-dynamic-vlan/td-p/3494603

s.van
Level 1
Level 1

Thankyou so much for the reply and the planned resolution.

Is there any timelines as to when this will be available as GA ?

No problems. Timelines are commercially sensitive and subject to change, so not appropriate to share in this forum unfortunately. The fix is not coming out for general consumption in the near term, but should be available later this year. If you need specific details please talk to your Cisco sales representative.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: