cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6005
Views
6
Helpful
6
Replies

best practice for Dynamic VLAN

yongwli
Cisco Employee
Cisco Employee

Hi Experts,

Customer want to assign VLAN for employee passed posture check, but there are not many departments defined in their AD. For separating broadcast domain, they would use VLAN for each floor. It cause too many policies(>300) need to be used in ISE. Any suggestion for this?

Do we have best practice for dynamic VLAN policy in ISE?

Thanks

DL

1 Accepted Solution
6 Replies 6

Jason Kunst
Cisco Employee
Cisco Employee

What about configuring vlan based on name?

Each switch has the same name for posture vlan but on each switch the subnet is different depending on the need

So you would only need one rule for this

If you had other vlans you could duplicate this method

dmh
Level 5
Level 5

If I understand your question correctly, you have lots of floors that require different VLANs to be dynamically assigned, to reduce the size of the broadcast domain, once authenticated and posture check is performed.

The way I implement this without a large complex policy is by using dynamic VLAN assignment by name and not ID and use a standard name across all floor switches that maps locally on each switch to a particular VLAN ID. So the policy for authenticated/checked users/computers is to assign to the VLAN EMPLOYEE (say) in the ISE result, however, on the switches on floor 1 this VLAN name maps to VLAN ID 101 and on floor 2 this VLAN name maps to VLAN ID 102 and so on for as many floors and buildings as you need. The policy remains very simple and the different broadcast domain mapping is done on the access switches where the VLANs must be configured anyway but you just use a standard name across all access switches.

This can be done for multiple VLANs if required.

The standard VLAN naming is only required on the access switch where 802.1x is required so for distribution switches etc you can use a more detailed name if required.

Hi @hariholla ,

Regarding the VLAN group, how will the switch distribute it to the users? via round-robin or FIFO?

Besides using the vlan group, can I just change the VLAN name as the same across the switches then call the name in ISE?

Thanks for the help.

 

yongwli
Cisco Employee
Cisco Employee

Hi Holla, Jason, dmh,

Thanks a lot! let me have a try.

DL

danielsai
Level 1
Level 1

Hi DL,

The easiest way to solve the issue would be eliminate the broadcast domain between Access Switch to Core(or)Dist switch.

By doing that you can assign same VLAN ID for all access switch, minimize the rules in the ISE and you can differentiate users from different floors by different IP address.

Else the rules in the ISE would keep increasing and it would be a nightmare for administrator to manage or troubleshoot the rules.

Eg.

Capture.PNG

Regards,

Sai