07-12-2025 05:07 AM
I was looking into using adaptive policy and it seems that objects can only be matched on CIDR. I was wanting to use it in lieu of Smartports not being supported on any of the Catalyst based switches. This would require matching on MAC or something else that does not seem to be supported.
Is there a way of putting IoT devices of a known type into a specific VLAN other than Smartports? Or is there a plan to roll Smartports out to the C9x00 switches?
07-12-2025 06:49 AM
Unfortunately none of the C9X00 switches offer smartports (and I doubt it ever will), believe you’d need to adopt Cisco ISE into this equation to achieve your goal.
I am not familiar enough with Cisco DNA to understand if it might offer an alternative solution but it may?
07-12-2025 07:05 AM
I
@CMR wrote:I was looking into using adaptive policy and it seems that objects can only be matched on CIDR. I was wanting to use it in lieu of Smartports not being supported on any of the Catalyst based switches. This would require matching on MAC or something else that does not seem to be supported.
Is there a way of putting IoT devices of a known type into a specific VLAN other than Smartports? Or is there a plan to roll Smartports out to the C9x00 switches?
Yes, using MAB with RADIUS or profiling with ISE on Catalyst C9k. On Meraki MS, also possible via MAB (but less granular, no native profiling).
07-12-2025 09:38 AM
Thanks @alessandrodematos using MAB and then selecting Access Manager and picking MAC address might do what I want. Time to experiment!
07-13-2025 06:04 PM
You could use Meraki Access Manager and the MAB feature to assign SGT tags.
07-25-2025 06:35 AM
I always hated smartports on Cisco small business switches since they would destroy your network just by connecting one type of device on a port.
However I don't really get OP's question.
The application of the correct tag happens only happens on IP as a last resort. You're supposed to use a radius solution and profiling to assign the correct tag to the session because the tag itself is just an identifier that helps for policy enforcement.
07-25-2025 12:13 PM
@joey.debra are you referring to me as OP? If so I wasn't trying to use IP, I wanted to use MAC address and I don't want the headache of running a RADIUS solution where I have a cloud managed network. @alessandrodematos's suggestion might be the way forward in the Merakiverse, unfortunately I haven't had a chance to test it yet...
07-26-2025 10:47 AM
I see. Well for modern workplace kind of customers that don't want to run own server, you can use access manager as the radius solution. that gives you 802.1x + MAB with an easy tagging method.
However you can just put an adaptive policy tag on a switchport if you want 😉
What I took away from the whole trustsec/adaptive policy is that the solution is meant to do away with VLAN sprawl which I really get. Because yes I have customers with small branch sites that sport 20+ VLANs just to have some policies between them.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide