cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
611
Views
0
Helpful
6
Replies

VLAN Steering and MAB authentication

Jim Blake
Level 1
Level 1

This question relates to a network of 9130 APs, managed by a 9800 WLC. I'm  trying to reduce the number of SSIDs being used in the network.

 

One of the reasons for having so many SSIDs is that there are several communities of wireless IoT devices that have no 802.1x capability, so must be authenticated using MAB. That would be fine, if all IoT devices needed to go into the same VLAN. However, there are families of devices, each one needing to be handled differently, so they are put I to different SSIDs/WLANs/VLANS, hence the high SSID count.

 

I'd like to use the ISE that handles 802.1x to do VLAN steering, so that I could use the same SSID, then steer client devices into different VLANs based upon their MAC address. I've  read about doing this with something called MyDevice Portal, but I haven't  found details on this, or if it's possible.

 

Can anyone say if what I propose is possible, and if so, point me at some documentation that will get me started

 

Thanks

 

Jim

 

1 Accepted Solution

Accepted Solutions

Yeah this is exactly what this could be used for, as long as the IoT device is capable of WPA2/AES with a PSK. 

It takes some additional ISE configuration though, because you need to create a profile for each VLAN you want to assign. 

In my opinion it would probably be better to put them all into the same VLAN and make sure that this VLAN is correctly isolated.

View solution in original post

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

You can create profiles based on that you can give access permission: you can use vendor OUI (when you use MAB authentication)

 

https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi

 From the ISE side your challange is to identify the device you want to spread on the vlans. You can work with profile. On the WLC side, you need to enable "Allow AAA Override" on the WLC, advanced tab

 On the AP group, instead poniting the WLAN to a interface group, you need to point to a non-routable interface.  But, you need to add the vlan on the WLC under "CONTROLLER" and Interfaces.

The IoT devices have no 802.1x supplicant, but lets assume they could handle iPSK. Can the ISE do VLAN steering based upon each different user/group's PSK? If that were possible, that could be a simple solution

Thanks

Jim

Yeah this is exactly what this could be used for, as long as the IoT device is capable of WPA2/AES with a PSK. 

It takes some additional ISE configuration though, because you need to create a profile for each VLAN you want to assign. 

In my opinion it would probably be better to put them all into the same VLAN and make sure that this VLAN is correctly isolated.

That looks to be the way to go...I will lab it and see how it works. Thanks!

Review Cisco Networking products for a $25 gift card