cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
428
Views
0
Helpful
1
Replies

Catalyst 2950, VLAN, 802.1x and Cisco Secure ACS

jstickland
Level 1
Level 1

Hello, Im looking forward to dropping a user in the appropriate vlan after the eap processing is complete by ACS.

Does filter-id property mean vlan in acs? Wait, i think thats ACL. What property is vlan?

About the vlans, how do i specify them on the switch? Right now, the client pc is an utagged member of vlan 10. But what if the user logging into the station had a filter-id of 20?

Would i be able to make the switch port an untagged member of 10 and 20 vlan? I could see tagging the port for multiple vlans okay, pending the client machine had a dot1q capable nic.

How is the switch port supposed to be a member of a vlan specified by the radius server, when the specified vlan is based on the user's group?

1 Reply 1

jstickland
Level 1
Level 1

Hmm...i think the IEEE radius authorization attribute for vlan is "tunnel private-id group"

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card