cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
414
Views
0
Helpful
3
Replies

VLANs per ACS server

deanyoung
Level 1
Level 1

Hi,

I would like to know if the following scenario is possible:

Let users in VLAN A authenticate to ACS A and users in VLAN B authenticate to ACS B.

Any comments welcome.

Regards

Dean

3 Replies 3

darpotter
Level 5
Level 5

I suspect this would depend on the device.

On an aironet AP you can tie an SSID to a vlan. You may even be able to tie an SSID to a particular AAA server.

Dont know other devices.

Darran

Alternatively, why not have one AAA and make that assign vlan based on some criteria. If a user is already on the network (in a vlan) isnt it a bit late to authenticate?

ACS v4.0 would allow you two select RADIUS profiles based on user group membership AND (for example) the device or any other attribute in the access request.

Darran

Thanks Darran. I presumed it would not be possible.