10-05-2025 07:09 PM
In the C9100 series EWC environment, I would like to dynamically assign a VLAN to each user (group) registered with the Radius server (Windows NPS). In the verification environment, VLAN information, etc. are passed from Radius to EWC in AVP, but client communication is not assigned to the specified VLAN. There were some examples in WLC9800, but can the setting work without problems in EWC?
Solved! Go to Solution.
10-06-2025 10:10 PM
Although it has been some time since the time of the inquiry, the information will be described as reference.
(1) It is better to check how the AVP (Attribute Value Pair) that the NPS of the Windows Server is trying to pass.
The following is the information of the AVP when specifying VLAN ID: 123 in the Authorization Profile for Dynamic VLAN in Cisco ISE.
Access Type = ACCESS_ACCEPT
Tunnel-Private-Group-ID = 1:123
Tunnel-Type = 1:13
Tunnel-Medium-Type = 1:6
(2) Since the EWC is running on the FlexConnect Local Switching, the VLAN definition on the wireless AP side must be performed on the Flex Profile.
(In the Cisco IOS-XE system, there is a vlan command, but it is the VLAN tab of the Flex Profile that defines the VLAN on the wireless AP side.) )
If the VLAN does not exist, you will see errors related to VLAN allocation failure in the log.
(3) You also need to enable AAA Override in Policy Profile to allow VLAN ID override.
Regarding the setting of Dynamic VLAN, the following is a reference in the Japanese translation document.
Configuring Dynamic VLAN Allocation Using ISE and Catalyst 9800 Wireless LAN Controllers - Cisco
https://www.cisco.com/c/ja_jp/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html
Also, I would like to add a link to the video of Mr. Minoura.
[Cisco ISE Capture Series] Dynamic VLAN - Wireless LAN (FlexConnect) [CCIE 5] - YouTube
https://www.youtube.com/watch?v=WlsMEU-8Mmw
10-05-2025 11:38 PM
check the docs for Limitation :
10-06-2025 04:26 PM
The example used here https://www.cisco.com/c/en/us/products/collateral/wireless/embedded-wireless-controller-catalyst-access-points/white-paper-c11-743398.html is using VLAN override so it should work. The guide in the previous reply is for EWC on Catalyst Switch.
10-06-2025 10:10 PM
Although it has been some time since the time of the inquiry, the information will be described as reference.
(1) It is better to check how the AVP (Attribute Value Pair) that the NPS of the Windows Server is trying to pass.
The following is the information of the AVP when specifying VLAN ID: 123 in the Authorization Profile for Dynamic VLAN in Cisco ISE.
Access Type = ACCESS_ACCEPT
Tunnel-Private-Group-ID = 1:123
Tunnel-Type = 1:13
Tunnel-Medium-Type = 1:6
(2) Since the EWC is running on the FlexConnect Local Switching, the VLAN definition on the wireless AP side must be performed on the Flex Profile.
(In the Cisco IOS-XE system, there is a vlan command, but it is the VLAN tab of the Flex Profile that defines the VLAN on the wireless AP side.) )
If the VLAN does not exist, you will see errors related to VLAN allocation failure in the log.
(3) You also need to enable AAA Override in Policy Profile to allow VLAN ID override.
Regarding the setting of Dynamic VLAN, the following is a reference in the Japanese translation document.
Configuring Dynamic VLAN Allocation Using ISE and Catalyst 9800 Wireless LAN Controllers - Cisco
https://www.cisco.com/c/ja_jp/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html
Also, I would like to add a link to the video of Mr. Minoura.
[Cisco ISE Capture Series] Dynamic VLAN - Wireless LAN (FlexConnect) [CCIE 5] - YouTube
https://www.youtube.com/watch?v=WlsMEU-8Mmw
10-07-2025 12:45 AM
Old community post about Winodws NPS dynamic vlan assignment
https://community.cisco.com/t5/wireless/dynamic-vlan-assignment-with-mobilityexpress-in-windows-radius/td-p/4117266
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide