cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2722
Views
0
Helpful
5
Replies

Dynamic VLAN assignment using ISE

z28thebridge
Level 1
Level 1

Hello All,

 

I was wondering if it is possible to use ISE (Version 2.4) to dynamically assign VLANs for wireless access points when they are plugged into a switchport. Our organization requires AP's to be on a separate VLAN from the user VLAN.

 

And if so, what steps do I need to take to implement this?

 

Thank you all!

5 Replies 5

marce1000
VIP
VIP

 

- As far as I understand yes, but probably only using MAB (Mac Authentication Bypass); the MAC addresses of the AP"s can be on an LDAP server (possibly MS AD-too). Switch with MAB-settings will use radius to query ISE. Configuration details require some basic studying of ISE.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

    Are those standalone AP's, or LAP's (which require a WLC to function)? If LAP's, are you running FlexConnect or not? It can be done anyways, but the solution depends on the above questions.

 

Regards,

Cristian Matei.

They are LAP's and we are running FlexConnect.

 

Thank you for your response!

kthiruve
Cisco Employee
Cisco Employee

As the other gentleman here said. Yes you can, but be careful since AP usually joins the wireless controller and needs an IP to join. If for some reason the DHCP fails and AP does not join, then you will have a problem.

 

You can probably whitelist the MAC address and assign a VLAN. As more AP's are used you can use the same whitelist to add AP MAC addresses.

 

You can also profile an AP that adds the MAC to endpoint ID group and use the endpoint ID group in the authorization policy.

Test these things before implementing it. Make sure your session for AP does not timeout very frequently causing reauthentication

 

Thanks

Krishnan

Hi,

 

  As MAB is really insecure in the end, even if it's combined with Profiling and Anomalous EndPoint Detection, i would chose to authenticate the AP via 802.1x. Depending on the WLC software/hardware model and LAP's you may be able to use EAP-TLS or EAP-PEAP; otherwise regardless of the WLC/LAP model, you can still use EAP-FAST. See the following guides for reference:

 

https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html?referring_site=RE&pos=3&page=https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexcon...

 

https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html

 

Regards,

Cristian Matei.