AAA, NAC, Guest Access & BYOD

 View Only
last person joined: one year ago 

Solutions for legacy and existing products and solutions, including Clearpass, CPPM, OnBoard, OnGuard, Guest, QuickConnect, AirGroup, and Introspect

Using VLAN pooling with Endpoint_Compliance_System (ECS) 

Jul 01, 2014 05:50 PM

The Endpoint Compliance System (ECS) could return either the VLAN ID or the role name to the controller via attribute in the Radius accept message. 

VLAN pooling allows the controller to populate users into set of VLAN defined in the virtual AP profile. 

If VLAN pooling is configured on the virtual AP profile, ECS must return the role name to the controller in the Radius accept message and in the role must not have any VLAN ID configuration. 

Example: 
user-role staff 
session-acl allowall 

wlan virtual-ap "vlanpooling" 
   vlan 100-102 

Note that the the Policy Enforcement Firewall (PEF) license is needed if you want to create custom user role. 

Note that the Default role is the role return to the controller after the users are registered and verified by the ECS.

 

vlanID.JPG

 

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.