cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
0
Helpful
1
Replies

Cisco ISE 1.3 - Mab authentication with different vlan for each foor

Augustgood
Level 1
Level 1

Hi, 

A customer wants to implement MAB authentication with different vlan for every floor. I found a tedius solution,

i configure the following:

-  different authentication profile with different vlan.

- add endpoint (printer etc) on identity endpoint.

- create identity group endpoint that recall endpoint.

- at the end i create  a rule of authorizzation that recall all element .... and Work.

 

You know if there is a faster way to or another way to solve the problem ?

 

thanks all

1 Accepted Solution

Accepted Solutions

jan.nielsen
Level 7
Level 7

Well, mab in some environments, could be replaced by profiling, and for the rules, instead af having an authz rule for each floor, you could name your vlans in your switches the same name for "Printers", everywhere, then you would only need one authz rule, where you use the name of the vlan instead of the id number, then it doesn't matter where that printer is located, it will end up in the "Printer" vlan, whatever that might be in that specific switch.

View solution in original post

1 Reply 1

jan.nielsen
Level 7
Level 7

Well, mab in some environments, could be replaced by profiling, and for the rules, instead af having an authz rule for each floor, you could name your vlans in your switches the same name for "Printers", everywhere, then you would only need one authz rule, where you use the name of the vlan instead of the id number, then it doesn't matter where that printer is located, it will end up in the "Printer" vlan, whatever that might be in that specific switch.