cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
128
Views
0
Helpful
5
Replies

Catalyst 9200L, NAC, dot1x, and multiple vlans on an access port

WILLIAM BAUER
Level 1
Level 1

I had a bit of a surprise making some changes to our planned NAC setup, and I want to make sure this is not a bug and is an expected behavior.  It's great if this is "normal".

We have 9200L access switches and ISE 3.1 in place.  The switch ports use dot1x and some simple profiling and posture policies on ISE.  All is working well.  While I knew that a single access port can have multiple hosts connected and each treated uniquely by NAC--such as with an ACL or posture state--what I didn't expect is that each can be on a different vlan.  This is not a question of trunking or pruning, and not a question about an IP phone.  Just an access port behavior.

The port in question is a host bridging multiple VMs and not using NAT.  If each client logs in with dot1x, which is our policy, I found each can be in a different vlan and operate normally.  I should note the VLANs are assigned by ISE.  Surprise!  Is this an expected behavior of NAC and a Catalyst 9200L?  The VM host is not configured for vlan tagging.  It's just my desktop.

Hope I explained it well enough.  I want to make sure we're not leveraging a bug or unintended behavior if we use this for special situations like the one I have.

1 Accepted Solution
5 Replies 5

Great!  Good to know I didn't stumble across another bug--I'm the bug finder....

Anyone working with Cisco now a days  end up being a Bug finder LOL

if you connect single host then use ISE can push vlan ID to your SW and SW assign this VLAN ID to port host connect to.

Multi host is different story.

It is not bug but sure you will see bug in some step of config.

MHM

Thanks

MHM