cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
656
Views
5
Helpful
6
Replies

what's configuration i need to do for assign different VLAN to different users via 802.1x on ISE?

sbmc014
Level 4
Level 4

There are two users in this environment , alex & dlink :

different users.jpg

and i already enable IETF 802.1x on network device profile :

set permit ietf 802.1x.jpg

but i don't know where i can configure different VLAN to different users ?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

For simple VLAN ID/name, we specify VLAN under the common tasks in an authorization profile. If using a user-attribute, then use the Advanced Attributes Settings for the three tunnel attributes.

Screen Shot 2018-05-08 at 9.55.00 PM.png

View solution in original post

6 Replies 6

hslai
Cisco Employee
Cisco Employee

For simple VLAN ID/name, we specify VLAN under the common tasks in an authorization profile. If using a user-attribute, then use the Advanced Attributes Settings for the three tunnel attributes.

Screen Shot 2018-05-08 at 9.55.00 PM.png

thanks for your reply , it can work now , but both of users are assigned the same VLAN , if i want assign different VLAN to different users , where i need to configure ?

Here is a post showing an example how you can assign a vlans per user

Dynamic Attribute with ISE: VLAN Assignment

cheers for this, spot on.

only question is, playing on a test server, our DC Team wonder if can do this by security group and add users in to it instead of by AD attribute for user?

Cheers

If using AD groups, then please create separate authorization policy rules to assign the VLANs.

If AD-group-1 then AuthZ-Profile-1-with-VLAN-A

If AD-group-2 then AuthZ-Profile-2-with-VLAN-B

...

Hi,

Confirmation, we've got over 15,000 users, if enable this, is it a default setting for all users, or can we just pick the users we want?

cheers