07-31-2013 03:30 PM - edited 03-10-2019 08:42 PM
Hi All,
Can ISE place a connection into a VLAN based on MAC address? (Both wired and wireless).
Scenario is as follows:
Thanks for your comments!
Andrew
Solved! Go to Solution.
07-31-2013 04:07 PM
If you create a rule per location then yes.
If a rule per location is not suitable then you could use one rule, which dumps them in to a vlan based on the vlan name, but then you obviously need separate vtp domains per location.
Careful when you dynamically allocate vlans that you may need to change to port bounce for COA to allow DHCP to do its thing, which is a global setting up until version 1.2.
Version 1.2 also has other flexibilities which might be useful to you (nested rules so I believe you may be able to have one rule with multiple profiles based on location), but I've not played with them too much yet.
Sent from Cisco Technical Support iPhone App
07-31-2013 07:09 PM
You have to create location based rule in ISE then it is possible. ISE 1.2 is providing lots of feature on location basis. Please check the release notes of ISE 1.2
07-31-2013 04:07 PM
If you create a rule per location then yes.
If a rule per location is not suitable then you could use one rule, which dumps them in to a vlan based on the vlan name, but then you obviously need separate vtp domains per location.
Careful when you dynamically allocate vlans that you may need to change to port bounce for COA to allow DHCP to do its thing, which is a global setting up until version 1.2.
Version 1.2 also has other flexibilities which might be useful to you (nested rules so I believe you may be able to have one rule with multiple profiles based on location), but I've not played with them too much yet.
Sent from Cisco Technical Support iPhone App
07-31-2013 07:09 PM
You have to create location based rule in ISE then it is possible. ISE 1.2 is providing lots of feature on location basis. Please check the release notes of ISE 1.2
08-01-2013 12:42 PM
Bike, Ravi,
Thank you both for the quick and great responses. Very valuable info.
I still have reluctance to implement things this way for more of a human rather than technical reason.
The customer is proposing they will have two MAC adddress lists, one for "trusted" corporate devices and one for "not so trusted" devices. I see that being the weak link in the policy more than anything.
Again, thanks for the comments.
Andrew
07-24-2018 05:05 AM
Hi,
I have a similar same. I configured mab authentication on 3750 cisco switch (Version 12.2(44r)SE3) for dynamic assigned vlan but when I pluged my laptop to switch port, my laptop cannot assign to desired vlan. Please take a look configured in my attached.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide