cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1613
Views
3
Helpful
6
Replies

Flexconnect AP Native vlan

OdenseKommune
Level 1
Level 1

Hi

I new to ISE and so is my colleague, and we are still learning a lot.

We have run into a problem regarding getting a native vlan, on a port that we connect a Cisco 3602I Access Point to.

The 802.1x works like a charm.

The AP Native VLAN is 666

And our switch port config is below.

My question is how we get a native vlan of 666 on the port?

Default port config:

switchport access vlan 5

switchport mode access

switchport nonegotiate

ip arp inspection trust

authentication event server dead action authorize vlan 40

authentication event server alive action reinitialize

authentication host-mode multi-auth

authentication order dot1x mab

authentication priority dot1x mab

authentication port-control auto

authentication periodic

authentication timer reauthenticate server

authentication violation restrict

mab

dot1x pae authenticator

dot1x timeout tx-period 10

spanning-tree portfast

ip dhcp snooping trust

Regards,

Brian Møller

6 Replies 6

Are you looking to just set the port to 666?

switchport access vlan 666


Or are you looking to have ISE change the vlan?

This should be able to be done by the result of the rule.

Capture.JPG

I have not tried this via wired, so there may be some other config needed.

Hi Dustin

Sorry i forgot a few ekstra informations in my first post.

We want the AP-port to have this ekstra config, or something simelar that works:

switchport mode trunk

switchport trunk native vlan 666

Regards,

Brian

OK, I think what you may want is to set an interface template.

Identity-Based Networking Services Configuration Guide, Cisco IOS Release 15E - Interface Templates [Cisco IOS 15.2E] …

http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ibns/configuration/xe-3e/ibns-xe-3e-book/ibns-int-temp.pdf

Granted it looks like it's dependent on ios version on the switch.

You could then call the template in the result on ISE.

hslai
Cisco Employee
Cisco Employee

You might want to take a look at this -- Configure to Secure a Flexconnect AP Switchport with Dot1x

Use interface-templates.

Screen Shot 2017-04-04 at 9.26.10 AM.png

run "show derived-config <interface>" to see the actual config applied on the port. The running-config won't change.

OdenseKommune
Level 1
Level 1

Hi Dustin and hslai

Thnx for the answers.

My Colleague and i will look at them and see what we can do.

Thnx

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: