05-30-2016 12:15 PM - edited 03-10-2019 11:49 PM
Hi
I have a requirement to setup ISE in such a way that it differentiates between switches within a switch stack. Does anyone know if there is an expression that I could use within an authorization compound condition that will achieve the following:
If a device using MAB connects to switch 1 in the stack it will be assigned to VLAN 10.
If the same device connects to switch 2 in the same stack it will be assigned to VLAN 20.
Thanks
Terry
Solved! Go to Solution.
05-30-2016 02:51 PM
You could use the interface numbering as a condition, the switch does not send any information about stack numbering. I don't remember the specific av pair, but you should be able to find it in the live log details.
05-30-2016 02:51 PM
You could use the interface numbering as a condition, the switch does not send any information about stack numbering. I don't remember the specific av pair, but you should be able to find it in the live log details.
05-31-2016 04:10 AM
Perfect, thanks Jan
Radius:NAS-Port-Id Starts with GigabitEthernet1/0/
Regards
Terry
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide