cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
467
Views
1
Helpful
2
Replies

Cisco ISE dynamic assign vlan for MAC in specific WiFi group of device

JSNascimento
Level 1
Level 1

Hello!

I have a WiFi network with Cisco WLC 5520 running well connecting with Cisco ISE 3.0 integrated with Microsoft AD.

But I want to implement another layer in the authentication fluxe to permit that all MACs should be verified if are part of a specific group. If this MACs are in the specific group these will receive a different and specific vlan.

Can anyone here give tips or indicate a document with instructions for this?

2 Replies 2

there are two attribute help here 
calling station ID <<- this MAC of Wifi user and you can use it as condition to specify  the VLAN 
called station ID 

MHM

Why, management of adding the MACs to a group is a pain. Then there is muliple operating systems starting to use randomise MAC address. Your setting yourself up for an admin nightmare.

You would be better doing EAP-TEAP authentication and verify the machine certificate and then user certificate/ PEAP for the user authentication.

That being said you can do it

WLAN: SSID 802.1x

ISE policy 802.1x, then in the Authz policy have line like if user in group A and calling station ID in endpoint group A return VLAN A

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card