cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1582
Views
5
Helpful
1
Replies

DNA Center, Subnet Directed Broadcast and smartports

ClaudeConnor
Level 1
Level 1

For a customer I'm trying to come up with a dynamic solution to configure a fabric switchport with a static access VLAN in support of their Wake-on-LAN based desktop support processes.

 

Specifically, DNAC v2.1.2.0 introduces support for Subnet Directed Broadcasts, which is great, but it also requires static host onboarding (according to the release notes), if I understand correctly. I'd rather find a solution that dynamicaly writes the VLAN send from ISE to the switchport.

 

In both cases, this would allow the PC to shutdown, while the last authorized VLAN remains active on the switchport and (in this case) SCCM is able to send a WoL magic packet to wake up that PC.

 

I've lookup into sticky templates, but that solution is not surviving a reload of the switch.

 

Now I'm looking into auto smart ports. Making the macro part of the ISE authorisation profile, the macro would be able to statically program the VLAN to the switchport.

 

I feel that in conjunction with a Closed Authentication policy, I should be able to keep the link-up and link-down triggers the same, so the VLAN config remains when the PC shuts down. Once the switchport reauthenticates a different use-case, another VLAN is written to the switchport.

 

Is the scenario "DNAC - ISE - Cat9000 - Smart Port macros" a viable solution or are there incompatibilities that would make this solution a no-go?

 

1 Reply 1

thomas
Cisco Employee
Cisco Employee

The above sounds very complicated.

Why aren't you just doing 802.1X with machine authentication for the computer?

Regardless of a restart or Wake on LAN it will authenticate properly to whatever VLAN/ACL/SGT you have ISE authorize it.