- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-01-2019 06:52 AM
Hi,
If I want to authorize users from a specific AD group access to a specific VLAN do I need to have that VLAN configured as an interface on the WLC?
Thanks,
-Jack
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-02-2019 04:03 AM
No you don't. You just need to have an Airespace ACL that's assigned to the user session by your policy server (e.g., ISE or ACS). The ACL will restrict all users except the authorized ones from accessing the destination subnet that's associated with the VLAN.
You could also alternatively use Scalable Group Tags (SGTs).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-02-2019 04:03 AM
No you don't. You just need to have an Airespace ACL that's assigned to the user session by your policy server (e.g., ISE or ACS). The ACL will restrict all users except the authorized ones from accessing the destination subnet that's associated with the VLAN.
You could also alternatively use Scalable Group Tags (SGTs).
