03-11-2020 09:05 AM
Hello All,
I was wondering if it is possible to use ISE (Version 2.4) to dynamically assign VLANs for wireless access points when they are plugged into a switchport. Our organization requires AP's to be on a separate VLAN from the user VLAN.
And if so, what steps do I need to take to implement this?
Thank you all!
03-11-2020 09:14 AM
- As far as I understand yes, but probably only using MAB (Mac Authentication Bypass); the MAC addresses of the AP"s can be on an LDAP server (possibly MS AD-too). Switch with MAB-settings will use radius to query ISE. Configuration details require some basic studying of ISE.
M.
03-11-2020 12:15 PM
Hi,
Are those standalone AP's, or LAP's (which require a WLC to function)? If LAP's, are you running FlexConnect or not? It can be done anyways, but the solution depends on the above questions.
Regards,
Cristian Matei.
03-12-2020 07:19 AM
They are LAP's and we are running FlexConnect.
Thank you for your response!
03-11-2020 12:51 PM
As the other gentleman here said. Yes you can, but be careful since AP usually joins the wireless controller and needs an IP to join. If for some reason the DHCP fails and AP does not join, then you will have a problem.
You can probably whitelist the MAC address and assign a VLAN. As more AP's are used you can use the same whitelist to add AP MAC addresses.
You can also profile an AP that adds the MAC to endpoint ID group and use the endpoint ID group in the authorization policy.
Test these things before implementing it. Make sure your session for AP does not timeout very frequently causing reauthentication
Thanks
Krishnan
03-12-2020 08:56 AM
Hi,
As MAB is really insecure in the end, even if it's combined with Profiling and Anomalous EndPoint Detection, i would chose to authenticate the AP via 802.1x. Depending on the WLC software/hardware model and LAP's you may be able to use EAP-TLS or EAP-PEAP; otherwise regardless of the WLC/LAP model, you can still use EAP-FAST. See the following guides for reference:
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide