Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass / Cisco Wired - Named VLAN Enforcement

This thread has been viewed 15 times
  • 1.  ClearPass / Cisco Wired - Named VLAN Enforcement

    MVP
    Posted Oct 24, 2017 03:14 PM

    Hey all,

     

    I've been searching around and can't seem to find the answer. If I'm doing wired 802.1X with cisco 2960X that supports named VLANs, what do I need to configure in CPPM enforcement profile to send named VLAN back?

     

    My thoughts: Enforcement type - VLAN Enforcement.  Private-Tunnel-ID set as VLAN name instead of VLAN number, but don't know if that's going to work.

     

    Can anyone show the proper way of doing this?

     

    Thanks.



  • 2.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement
    Best Answer



  • 3.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    MVP
    Posted Oct 24, 2017 03:20 PM

    Page 117, that's exactly what I'm looking for. That document will actually help with some other stuff I'm doing too, thanks for the help!



  • 4.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    Posted Jun 01, 2018 02:47 PM

    hello Tim

    i went through your document, and it helps a lot, 

    for Cisco IOS section, i'm wondring how you configured the enforcement profile of EDGE_GUEST(vlan name)  

    i tried the bellow but doesn't work 

    profile template : Vlan enforcement 

    and instead of : 

     Type: Radius:IETF         name:Tunnel-Private-Group-Id    value: 200

    i changed it with: 

    Type: Radius:IETF        name: Egress-VLAN-Name           value: DATAVLAN

     

    But it doesn't work unfortunetly 

     

    note: in my cisco switch vlan id : 200 is named DATAVLAN

     

    waiting for your feedback Tim  

     



  • 5.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    EMPLOYEE
    Posted Jun 01, 2018 03:09 PM
    The VLAN name goes as Tunnel-Private-Group-Id as documented.


  • 6.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    Posted Jun 02, 2018 08:02 PM
    hello Tim,
    witch mean
    Type: Radius:IETF name:Tunnel-Private-Group-Id value: DATAVLAN
    should work for my case right ?



  • 7.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    EMPLOYEE
    Posted Jun 03, 2018 05:30 AM
    Yes.


  • 8.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    Posted Dec 16, 2019 07:34 PM

    Hi,

     

    Great document and post,this:Type: Radius:IETF name:Tunnel-Private-Group-Id value: DATAVLAN

     

    will look for the exact name vlan or even if contain the keyworks DATAVLAN should works?  examplae:

     

    vlan id:    coporate-datavlan

     

    greetings



  • 9.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    MVP
    Posted Dec 16, 2019 07:50 PM
    Has to be exact match to VLAN name already on switch.


  • 10.  RE: ClearPass / Cisco Wired - Named VLAN Enforcement

    Posted Dec 16, 2019 07:51 PM

    thank you!