cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
961
Views
0
Helpful
5
Replies

Host Onboarding Vlan ID Modification

Hi, 

 

I would like to know if it is possible to modify the vlan ID assigned dynamically  when host onboarding provisioning  is configured. 


if it is possible, i would like to know how i can do it.

 

Br, 

Fidel Gonzalez

1 ACCEPTED SOLUTION

Accepted Solutions
ldanny
Cisco Employee

Hi Fidel,

Please see following Guide on How to Onboard Endpoints with ISE in SD-Access.

How to SDA Host Onboarding with ISE

View solution in original post

5 REPLIES 5
Mariusz Kazmierski
Cisco Employee

Hi, 

 

If you go with dot1x/mab/easy auth on host-onboarding, then VLAN ID can be assigned based on policy configured in ISE (VLAN ID should be still the one that was originally provisioned by DNA-Center when IP Pools were first added). 

 

Please refer to "Cisco DNA Center Fast Start Use Case: Software-Defined Access Guide" (section: Configure dynamic authentication with ISE):

https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/software-defined-access/guide-c07-741859.html#_Toc2934408

 

Best regards,

Mariusz

Mike.Cifelli
VIP Advisor

@Mariusz Kazmierski is definitely right with the dynamic assignment via ISE.  Adding additional information:

You can utilize the DNAC template editor to modify default auth template configs.  For example, using the editor you can modify the DNAC critical auth vlan that gets used in the DefaultCriticalAuthVlan service-template.  You can also utilize the template editor to tweak other standard configs that get deployed from the out-of-box auth templates.  HTH!

Hi Mike, 

 

This is really what i want,  i will try to do it.

 

 

is there  something specific that  i need to know? 

 

I am new in SDA.

 

Br, 

Fidel Gonzalez

Hi Mike,

Can i modify the vlan ID when the host onboarding was already configured?

I have already configured the host onboarding, the problem is that I am using Virtual machines, I have a port channel (Trunk Mode) on the edge switch, and several servers and vlans ( that was assigned before the host onboarding) on the VMWare.

I have a mismatch between the vlans configured on the VMs and the vlans assigned by the host onboarding process, I would like to modify the vlan assigned by the host onboarding process.

is it possible?


ldanny
Cisco Employee

Hi Fidel,

Please see following Guide on How to Onboard Endpoints with ISE in SD-Access.

How to SDA Host Onboarding with ISE