cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
304
Views
1
Helpful
4
Replies

Is it possible to allocate dynamic VLANs on a per-user basis in an EWC environment?

Translator
Community Manager
Community Manager

In the C9100 series EWC environment, I would like to dynamically assign a VLAN to each user (group) registered with the Radius server (Windows NPS). In the verification environment, VLAN information, etc. are passed from Radius to EWC in AVP, but client communication is not assigned to the specified VLAN. There were some examples in WLC9800, but can the setting work without problems in EWC?

1 Accepted Solution

Accepted Solutions

Translator
Community Manager
Community Manager

Although it has been some time since the time of the inquiry, the information will be described as reference.

(1) It is better to check how the AVP (Attribute Value Pair) that the NPS of the Windows Server is trying to pass.
The following is the information of the AVP when specifying VLAN ID: 123 in the Authorization Profile for Dynamic VLAN in Cisco ISE.

Access Type = ACCESS_ACCEPT
Tunnel-Private-Group-ID = 1:123
Tunnel-Type = 1:13
Tunnel-Medium-Type = 1:6

MyHomeNWLab_0-1759812706440.png


(2) Since the EWC is running on the FlexConnect Local Switching, the VLAN definition on the wireless AP side must be performed on the Flex Profile.
(In the Cisco IOS-XE system, there is a vlan command, but it is the VLAN tab of the Flex Profile that defines the VLAN on the wireless AP side.) )
If the VLAN does not exist, you will see errors related to VLAN allocation failure in the log.

MyHomeNWLab_1-1759812934297.png


(3) You also need to enable AAA Override in Policy Profile to allow VLAN ID override.

MyHomeNWLab_2-1759812998155.png



Regarding the setting of Dynamic VLAN, the following is a reference in the Japanese translation document.

Configuring Dynamic VLAN Allocation Using ISE and Catalyst 9800 Wireless LAN Controllers - Cisco
https://www.cisco.com/c/ja_jp/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html


Also, I would like to add a link to the video of Mr. Minoura.

[Cisco ISE Capture Series] Dynamic VLAN - Wireless LAN (FlexConnect) [CCIE 5] - YouTube
https://www.youtube.com/watch?v=WlsMEU-8Mmw

View solution in original post

4 Replies 4

Rich R
VIP
VIP

The example used here https://www.cisco.com/c/en/us/products/collateral/wireless/embedded-wireless-controller-catalyst-access-points/white-paper-c11-743398.html is using VLAN override so it should work.  The guide in the previous reply is for EWC on Catalyst Switch.

Translator
Community Manager
Community Manager

Although it has been some time since the time of the inquiry, the information will be described as reference.

(1) It is better to check how the AVP (Attribute Value Pair) that the NPS of the Windows Server is trying to pass.
The following is the information of the AVP when specifying VLAN ID: 123 in the Authorization Profile for Dynamic VLAN in Cisco ISE.

Access Type = ACCESS_ACCEPT
Tunnel-Private-Group-ID = 1:123
Tunnel-Type = 1:13
Tunnel-Medium-Type = 1:6

MyHomeNWLab_0-1759812706440.png


(2) Since the EWC is running on the FlexConnect Local Switching, the VLAN definition on the wireless AP side must be performed on the Flex Profile.
(In the Cisco IOS-XE system, there is a vlan command, but it is the VLAN tab of the Flex Profile that defines the VLAN on the wireless AP side.) )
If the VLAN does not exist, you will see errors related to VLAN allocation failure in the log.

MyHomeNWLab_1-1759812934297.png


(3) You also need to enable AAA Override in Policy Profile to allow VLAN ID override.

MyHomeNWLab_2-1759812998155.png



Regarding the setting of Dynamic VLAN, the following is a reference in the Japanese translation document.

Configuring Dynamic VLAN Allocation Using ISE and Catalyst 9800 Wireless LAN Controllers - Cisco
https://www.cisco.com/c/ja_jp/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html


Also, I would like to add a link to the video of Mr. Minoura.

[Cisco ISE Capture Series] Dynamic VLAN - Wireless LAN (FlexConnect) [CCIE 5] - YouTube
https://www.youtube.com/watch?v=WlsMEU-8Mmw

srimal99
Level 1
Level 1
Review Cisco Networking for a $25 gift card