07-18-2006 06:37 AM - edited 03-10-2019 02:40 PM
Hi,
I would like to know if the following scenario is possible:
Let users in VLAN A authenticate to ACS A and users in VLAN B authenticate to ACS B.
Any comments welcome.
Regards
Dean
07-18-2006 07:20 AM
I suspect this would depend on the device.
On an aironet AP you can tie an SSID to a vlan. You may even be able to tie an SSID to a particular AAA server.
Dont know other devices.
Darran
07-18-2006 07:23 AM
Alternatively, why not have one AAA and make that assign vlan based on some criteria. If a user is already on the network (in a vlan) isnt it a bit late to authenticate?
ACS v4.0 would allow you two select RADIUS profiles based on user group membership AND (for example) the device or any other attribute in the access request.
Darran
07-18-2006 10:37 PM
Thanks Darran. I presumed it would not be possible.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide