dynamic vlan assignment besides vmps
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

dynamic vlan assignment besides vmps

 
Post new topic   Reply to topic    Forum Index -> comp.dcom.sys.cisco
Author Message
psychogenic
Guest





PostPosted: Thu Apr 20, 2006 6:06 pm    Post subject: dynamic vlan assignment besides vmps Reply with quote

Hey all,

Am wonderng if there are any other solutions for dynamic assignment of
vlans other than URT (whihc seems overly expensive) and VMPS (server
only seems to work on CatOS whihc none my switches run)? Basically I
want to set up a conference room and our guest area where any unknown
MAC addresses that gets plugged in will b e sent on one vlan and
trusted laptops in our network gets put on another.

Thanks!
Back to top
Merv
Guest





PostPosted: Thu Apr 20, 2006 6:12 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

Well if you have a RADIUS server, then see

http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_guide_chapter09186a00801d0189.html#1038739
Back to top
Merv
Guest





PostPosted: Thu Apr 20, 2006 6:40 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

Or perhaps you could set up two VLANS - one with an open SSID (for
guest) and the other SSID can be authenticated (using FAST_EAP for
example).

You could also apply a MAC filter to the secure SSID using the
dot11 association mac-list command.
Back to top
psychogenic
Guest





PostPosted: Thu Apr 20, 2006 6:43 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

I do but can that also be applied to a wired network (not touching
wireless yet)?

Thanks.

Merv wrote:
Quote:
Well if you have a RADIUS server, then see

http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_guide_chapter09186a00801d0189.html#1038739
Back to top
Merv
Guest





PostPosted: Thu Apr 20, 2006 6:57 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

what switch and IOS version ?
Back to top
psychogenic
Guest





PostPosted: Thu Apr 20, 2006 7:11 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

backbone is 6500 running IOS v 12.2, and our on floor switches are made
up of 3550s and some 3500XLs, all running IOS v 12.2

Merv wrote:
> what switch and IOS version ?
Back to top
Merv
Guest





PostPosted: Thu Apr 20, 2006 7:16 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

take a look at 802.1x authentication and dynamic VLAN assignment

http://www.cisco.com/en/US/products/hw/switches/ps5528/products_configuration_guide_chapter09186a00801e85c4.html#1062632
Back to top
psychogenic
Guest





PostPosted: Thu Apr 20, 2006 7:29 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

Hmm, would this break tacacs+ on the switches? I've added them all to
SecureACS for authentication and authorization for the admins here, and
also am using local accounts on the devices in case the ACS server is
unreachable.


Merv wrote:
Quote:
take a look at 802.1x authentication and dynamic VLAN assignment

http://www.cisco.com/en/US/products/hw/switches/ps5528/products_configuration_guide_chapter09186a00801e85c4.html#1062632
Back to top
Merv
Guest





PostPosted: Thu Apr 20, 2006 8:23 pm    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

If you have SecureACS then take a look at the Network Admission Control
feature (NAC)

http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a00805ec1ad.html
Back to top
C Kim
Guest





PostPosted: Fri Apr 21, 2006 12:09 am    Post subject: Re: dynamic vlan assignment besides vmps Reply with quote

No. Dot1x will not break tacacs+. two separate things.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> comp.dcom.sys.cisco All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory