05-08-2018 03:19 AM - edited 02-21-2020 10:55 AM
Hi Cisco community,
Is it possible for Cisco ISE to dynamically assign user VLANs from a pool of possible VLANs on a round robin fashion?
Solved! Go to Solution.
05-09-2018 06:38 AM
Unfortunately Flex isn’t really geared to large sites or large numbers of users. Flex can’t use groups like you describe. The ‘best’ solution would be to use a WLC I’m afraid.
05-08-2018 03:45 AM
05-08-2018 04:48 AM
No, but you can tell ISE to supply a pool name and you just let the device with the pool do the actual load balancing... Cisco WLCs and Catalyst Switches both support VLAN pools.
05-08-2018 06:30 AM
Thanks for the info. Are there any configurations example for this? I could not find any online
05-08-2018 09:48 PM
05-08-2018 10:41 PM
Yep, so ‘interface groups’ in the WLC is equivalent to ‘VLAN-Group’ on a Catalyst switch. You define a group, add VLANs to it, then when you authenticate a new Client, you have ISE return the VLAN-Group name via RADIUS and the Switch will load-balance(ish) Users across all of the VLANs in the Group.
It is not a particularly well documented feature.
See here, page 9-56, ‘Configuring 802.1X User Distribution’;
VLAN Group [vlan-group-name] vlan-list [list-of-vlans]
05-09-2018 04:00 AM
What I'm trying to achieve is that I have several huge locally switched FlexConnect locations which I would like to put in one FlexConnect group due to roaming considerations. I would like to use AAA ACL mappings for more than 10 VLANs on the same FlexConnect Group and hence pre-configure all VLANs for all AP. Users would then be assigned to different VLANs in the same WLAN-SSID and be able to move around with the their IP on the premises.
05-09-2018 06:38 AM
Unfortunately Flex isn’t really geared to large sites or large numbers of users. Flex can’t use groups like you describe. The ‘best’ solution would be to use a WLC I’m afraid.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide