BACK TO SUPPORT PORTAL
RUCKUS Technologies
Wired
Wireless
Cloud Services
Miscellaneous
RUCKUS Lennar Support
Lennar Knowledge Base
RUCKUS Lennar Support
Resources
Community
Technical
Register
RUCKUS Technologies
Home
RUCKUS Technologies and Products
Access Points - Indoor and Outdoor
dynamic vlan assignment with ISE and AD
unknown
Hi dear friend
we want to use authenticate WiFi users with Cisco ISE, Also we want to assign vlan to users after authentication by cisco ISE, as note, ISE server is integrated with Micorosft AD for authentication, when a user see credential pop-up, send its credential to ISE, ISE check it with AD and assign a group/vlan to this user
this procedure doesnt work accurately on ZD 1200.
if u can, help me please
regards
Reza
Find more posts tagged with
Accepted answers
All comments
unknown
Hi Reza, do you need the ISE to authenticate? Depending on what you are using the ISE for, you could authenticate to AD using the ZD1200 and change the VLAN based on attributes returned from AD,VLAN switching using this method works reliably and is quick to setup. Then if you need user details into ISE send RADIUS accounting info to the ISE.
Hope this is useful.
Robert
roshan_menaka
Hi,
If your looking for Vlan assignment based on AD authentication unsure why need ISE for this ?
We have done a AD authentication with MS Radius and Dynamic Vlan with Ruckus unleashed.
It works perfectly .
unknown
Dear Robert
great reply
thank you
actually i dont need ISE basically
just i want to read different group from AD and assign VLANs to each group (user in group)
tell me this work with Dot1X?
would you help me how can i implement this on my network?
regards
Reza
unknown
Dear Friend
thanks for your reply
do u have any docs for implementing this?
i cant actually understand what should i do?
sending all Dot1X traffic to AD at first? or send other place?
and AD should work with NPS?
would you gimme more explain
regards
Reza
roshan_menaka
Hi,
I don't have any documentation for this. but i can tel you what we have done.
Basically you need a AD groups and NPS ( you can use the same AD server but recommended separate server for this)
Once your done with the NPS installation you can create network policies to assign vlan ID. this can be based on user groups.
To assign the vlan ID you need to user the following radius attributes.
Tunnel-Type = vlan
Tunnel-Assignment-ID = vlan ID
Tunnel-Medium-Type = 802.1x
Tunnel-Pvt-Group-ID = vlan ID
* This is total Microsoft NPS solution no ISE involvement. but i hope Cisco ISE has more options and better answer for your requirement.
michael_brado
KBA-2109: Configuring AD and NPS Radius Server
https://support.ruckuswireless.com/articles/000002109
Quick Links
🗂️ All Categories
📄 Recent Posts
❓ Unanswered
🆘 Help
Tags
SmartZone or vSZ
RUCKUS Self-Help
Cloudpath
ICX
AP Management
vSZ
Access points
ICX Switch Management
Lennar homes
SmartZone