01-28-2025 05:55 AM
Scenario: Printer is connected to WLAN network and authenticated to ISE using MAB
Problem: MAB Authentication is successful but the MAC address is currently learned at both VLANs
VLAN A = Default WLAN VLAN
VLAN B = Printer VLAN
I have setup the policy in ISE to match the endpoint group where the printer is located and to call an AuthZ profile to change the VLAN. I try to put a static IP on the same network as VLAN B but still not working.
Any thoughts.
Solved! Go to Solution.
01-28-2025 06:45 AM
Hello, Yes, actually just managed to solve this by removing the endpoint from the endpoint group, readding it was able to get the DHCP now.
01-28-2025 06:08 AM
What is the NAD? Is VLAN B actually present on the controller?
https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356
01-28-2025 06:15 AM
NAD is C9800 controller, the APs are in FLEX MODE, and yes the VLAN is on the controller as it was able to return it to the endpoint and I am seeing the endpoint in VLAN B as well.
01-28-2025 06:20 AM
01-28-2025 06:27 AM - edited 01-28-2025 06:30 AM
Problem is that the MAB endpoint is currently learned from two VLANs and the correct VLAN is not working as I am not seeing an ARP entry for the IP configured on the endpoint, and when I do via DHCP its not getting IP and the state of the endpoint is stuck in IP_LEARN. I verified that the there is no problem with the DHCP
01-28-2025 06:41 AM
01-28-2025 06:45 AM
Hello, Yes, actually just managed to solve this by removing the endpoint from the endpoint group, readding it was able to get the DHCP now.
01-28-2025 06:52 AM
Sorry I reply late but how endpoint authz with two vlan?
Can i ser how you config ISE?
MHM
02-01-2025 01:16 AM
I had a similar issue with dynamic VLAN assignment for my printer using MAB in Cisco ISE. The printer was being assigned to both VLAN A (default WLAN VLAN) and VLAN B (printer VLAN). After checking the policy and static IP settings, I realized the switch port wasn’t correctly configured for dynamic VLAN assignment. Once I corrected the switch port settings and ensured VLAN trunking was enabled, the printer was properly assigned to VLAN B.
This experience reminded me of optimizing network performance for gaming, like prioritizing gaming traffic to prevent lag—just like how we prioritize devices like printers to improve overall performance. Hope this helps!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide