Hi dear friend we want to use authenticate WiFi users with Cisco ISE, Also we want to assign vlan to users after authentication by cisco ISE, as note, ISE server is integrated with Micorosft AD for authentication, when a user see credential pop-up, send its credential to ISE, ISE check it with AD and assign a group/vlan to this user this procedure doesnt work accurately on ZD 1200. if u can, help me please
Hi Reza, do you need the ISE to authenticate? Depending on what you are using the ISE for, you could authenticate to AD using the ZD1200 and change the VLAN based on attributes returned from AD,VLAN switching using this method works reliably and is quick to setup. Then if you need user details into ISE send RADIUS accounting info to the ISE.
Dear Robert great reply thank you actually i dont need ISE basically just i want to read different group from AD and assign VLANs to each group (user in group) tell me this work with Dot1X? would you help me how can i implement this on my network?
If your looking for Vlan assignment based on AD authentication unsure why need ISE for this ? We have done a AD authentication with MS Radius and Dynamic Vlan with Ruckus unleashed. It works perfectly .
Dear Friend thanks for your reply do u have any docs for implementing this? i cant actually understand what should i do? sending all Dot1X traffic to AD at first? or send other place? and AD should work with NPS? would you gimme more explain