|
|
| Author |
Message |
psychogenic Guest
|
Posted: Thu Apr 20, 2006 6:06 pm Post subject: dynamic vlan assignment besides vmps |
|
|
Hey all,
Am wonderng if there are any other solutions for dynamic assignment of
vlans other than URT (whihc seems overly expensive) and VMPS (server
only seems to work on CatOS whihc none my switches run)? Basically I
want to set up a conference room and our guest area where any unknown
MAC addresses that gets plugged in will b e sent on one vlan and
trusted laptops in our network gets put on another.
Thanks! |
|
| Back to top |
|
 |
|
|
Merv Guest
|
|
| Back to top |
|
 |
Merv Guest
|
Posted: Thu Apr 20, 2006 6:40 pm Post subject: Re: dynamic vlan assignment besides vmps |
|
|
Or perhaps you could set up two VLANS - one with an open SSID (for
guest) and the other SSID can be authenticated (using FAST_EAP for
example).
You could also apply a MAC filter to the secure SSID using the
dot11 association mac-list command. |
|
| Back to top |
|
 |
psychogenic Guest
|
Posted: Thu Apr 20, 2006 6:43 pm Post subject: Re: dynamic vlan assignment besides vmps |
|
|
I do but can that also be applied to a wired network (not touching
wireless yet)?
Thanks.
Merv wrote:
|
|
| Back to top |
|
 |
Merv Guest
|
Posted: Thu Apr 20, 2006 6:57 pm Post subject: Re: dynamic vlan assignment besides vmps |
|
|
| what switch and IOS version ? |
|
| Back to top |
|
 |
psychogenic Guest
|
Posted: Thu Apr 20, 2006 7:11 pm Post subject: Re: dynamic vlan assignment besides vmps |
|
|
backbone is 6500 running IOS v 12.2, and our on floor switches are made
up of 3550s and some 3500XLs, all running IOS v 12.2
Merv wrote:
> what switch and IOS version ? |
|
| Back to top |
|
 |
Merv Guest
|
|
| Back to top |
|
 |
|
|
psychogenic Guest
|
Posted: Thu Apr 20, 2006 7:29 pm Post subject: Re: dynamic vlan assignment besides vmps |
|
|
Hmm, would this break tacacs+ on the switches? I've added them all to
SecureACS for authentication and authorization for the admins here, and
also am using local accounts on the devices in case the ACS server is
unreachable.
Merv wrote:
|
|
| Back to top |
|
 |
Merv Guest
|
|
| Back to top |
|
 |
C Kim Guest
|
Posted: Fri Apr 21, 2006 12:09 am Post subject: Re: dynamic vlan assignment besides vmps |
|
|
| No. Dot1x will not break tacacs+. two separate things. |
|
| Back to top |
|
 |
|