cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

276
Views
0
Helpful
5
Replies
Highlighted
Beginner

Dynamic VLAN assignment using ISE

Hello All,

 

I was wondering if it is possible to use ISE (Version 2.4) to dynamically assign VLANs for wireless access points when they are plugged into a switchport. Our organization requires AP's to be on a separate VLAN from the user VLAN.

 

And if so, what steps do I need to take to implement this?

 

Thank you all!

5 REPLIES 5
Highlighted
VIP Engager

Re: Dynamic VLAN assignment using ISE

 

- As far as I understand yes, but probably only using MAB (Mac Authentication Bypass); the MAC addresses of the AP"s can be on an LDAP server (possibly MS AD-too). Switch with MAB-settings will use radius to query ISE. Configuration details require some basic studying of ISE.

 M.

Highlighted
Collaborator

Re: Dynamic VLAN assignment using ISE

Hi,

 

    Are those standalone AP's, or LAP's (which require a WLC to function)? If LAP's, are you running FlexConnect or not? It can be done anyways, but the solution depends on the above questions.

 

Regards,

Cristian Matei.

Highlighted
Beginner

Re: Dynamic VLAN assignment using ISE

They are LAP's and we are running FlexConnect.

 

Thank you for your response!

Highlighted
Cisco Employee

Re: Dynamic VLAN assignment using ISE

As the other gentleman here said. Yes you can, but be careful since AP usually joins the wireless controller and needs an IP to join. If for some reason the DHCP fails and AP does not join, then you will have a problem.

 

You can probably whitelist the MAC address and assign a VLAN. As more AP's are used you can use the same whitelist to add AP MAC addresses.

 

You can also profile an AP that adds the MAC to endpoint ID group and use the endpoint ID group in the authorization policy.

Test these things before implementing it. Make sure your session for AP does not timeout very frequently causing reauthentication

 

Thanks

Krishnan

Highlighted
Collaborator

Re: Dynamic VLAN assignment using ISE

Hi,

 

  As MAB is really insecure in the end, even if it's combined with Profiling and Anomalous EndPoint Detection, i would chose to authenticate the AP via 802.1x. Depending on the WLC software/hardware model and LAP's you may be able to use EAP-TLS or EAP-PEAP; otherwise regardless of the WLC/LAP model, you can still use EAP-FAST. See the following guides for reference:

 

https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html?referring_site=RE&pos=3&page=https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexcon...

 

https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html

 

Regards,

Cristian Matei.