cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1014
Views
0
Helpful
4
Replies

ISE Questions - Urgent

rshehov
Cisco Employee
Cisco Employee

HI all,

 

Is it possible someone to help me out with the following questions in regards of ISE please ? 

 

Is it possible to achieve the following with ISE ? 

Publish single SSID for GovRoam

If internal user authenticated then dynamically assign user to a Corporate VLAN (Local

If External  user authenticated then route traffic via Guest Anchor controller

 

Thank you for your input in advance.

 

Regards

 

Ross

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

This is not possible due to WLC limitation. A given WLAN is either auto-anchored or not and it cannot be both non-anchored and auto-anchored based on user/endpoint currently. We can assign different VLANs based on user/endpoint type and guest VLAN can be mapped to a vrf that gets handled differently.

View solution in original post

4 Replies 4

howon
Cisco Employee
Cisco Employee

This is not possible due to WLC limitation. A given WLAN is either auto-anchored or not and it cannot be both non-anchored and auto-anchored based on user/endpoint currently. We can assign different VLANs based on user/endpoint type and guest VLAN can be mapped to a vrf that gets handled differently.

rshehov
Cisco Employee
Cisco Employee

Many thanks for your great input.

 

Regards

 

Ross

rshehov
Cisco Employee
Cisco Employee
I was thinking that we can route external users when authenticated to guest Anchor controller. However you mentioned that this is not possible. Is this the case or I am getting this one wrong ?

howon
Cisco Employee
Cisco Employee

When you have a WLAN mapped from foreign to anchor (guest), all traffic will get anchored regardless of who connects to the WLAN. One can't choose some users to be anchored on foreign controller and others through the anchor controller on the same WLAN.