08-22-2022 12:20 AM
I was wondering if anyone knows if its possible to change the multicast vlan on a wireless user via either a aaa attribute or Cisco AV Pair that can be returned from the radius server, in this case Cisco ISE. The WLC is a 9800 running 17.3 release code .
wireless profile policy XXXX-SSID
aaa-override
description XXXX
http-tlv-caching
multicast vlan 50
nac
radius-profiling
subscriber-policy-name BUILTIN_AUTOCONF_POLICY
vlan Test
no shutdown
I cannot find a list of aa attributes or cisco av-pairs that are supported for the 9800 in any of the online documentation.
08-22-2022 10:36 AM
The aaa attributes/av-pairs documentation is practically non-existent. It took about a month just to get a TAC engineer to understand a similar question recently and then they still couldn't find the answer even after they (sort of) understood the question. They just kept telling us to refer to ISE documentation instead of answering the question!
Your only hope is a TAC case - but good luck with that ...
02-09-2024 03:29 AM
This information is available via the cli, try show aaa attributes and show radius table attributes.
Hope that helps.
02-11-2024 07:38 AM
Thanks for that @brandjoh - good to know.
That said, I don't see anything that looks like multicast vlan which is what @Sean Aindow was asking about. Do you know whether there is any attribute for that?
02-12-2024 04:17 AM
what is the use case? Typically multicast vlan in use when you have vlan-group (known as 'interface-group' in AireOS ) and you want to specific vlan to send multicast request instead of all the vlans sending multicast requests in that group.
I do not think there is an option to use AAA override for it
HTH
Rasika
*** Pls rate all useful responses ***
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide